logo

GitLab Users Urged to Patch After Research Reveals Critical RCE Chain

ID: 4e3dd1f8-c9a1-58b1-a9d5-475489e96f27

STIX ID: report--4e3dd1f8-c9a1-58b1-a9d5-475489e96f27

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-07-27

Date Updated: 2026-07-27

Author: Pierluigi Paganini

...
...

**GitLab remote code execution via Oj parser:** Depthfirst published a working RCE exploit that chains two memory-corruption bugs in the Oj Ruby JSON parser used by GitLab’s Jupyter notebook diff renderer, allowing any authenticated user who can push and view commit diffs to execute commands as the git user on vulnerable Puma workers; affected GitLab CE/EE versions include 15.2.0–18.10.7, 18.11.0–18.11.4, and 19.0.0–19.0.1, and operators are advised to upgrade to 18.10.8, 18.11.5, or 19.0.2.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.