#gitlab


GitLab warns of critical RCE vulnerability in AI Gateway service

Oct 2, 2026 // 23:17

GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances. AI Gateway is […]

GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

Oct 2, 2026 // 23:15

A critical flaw in GitLab’s AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, […]

Exposed GitLab project email addresses let attackers push code

Sep 24, 2026 // 23:37

Private GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in READMEs, contributing guides, and support […]

CISA: Hackers now exploit max severity GitLab flaw in attacks

Sep 14, 2026 // 11:57

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are now exploiting a maximum-severity GitLab vulnerability in attacks. GitLab’s DevSecOps platform is used […]

GitLab urges users to patch max severity path traversal flaw

Sep 12, 2026 // 01:37

GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. The security flaw, discovered by a […]

⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

Aug 25, 2026 // 01:33

A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet. That’s roughly the mood this week. […]

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

Aug 18, 2026 // 00:07

GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could […]

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

Jul 25, 2026 // 12:10

Security researcher Yuhang Wu at depthfirst has published a working proof-of-concept (PoC) exploit that executes commands as git on an unpatched self-managed GitLab 18.11.3 server. […]