Leaked GitLab Email Tokens Can Let Attackers Push Code and Trigger CI Pipelines
Security researchers at Aikido Security have identified a high-severity vulnerability in GitLab's incoming email feature, where exposed email tokens can allow unauthorized third parties to modify code and execute CI pipelines. An attacker who obtains a valid incoming email address can send a crafted patch email, which GitLab processes under the permissions of the legitimate token owner. The flaw does not enable privilege escalation to other accounts, but a single leaked token can be exploited across multiple projects owned by the same user. No active exploitation in the wild has been reported, though the risk is rated high due to the long-lived nature of the tokens and their impact on development infrastructure. GitLab users are advised to reset exposed tokens, restrict branch and CI permissions, and — for self-managed instances — consider disabling the incoming email feature if unused.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in