logo

Two Old Oj Flaws Chained to Trigger GitLab Remote Code Execution

ID: e39cccb6-d869-579f-933f-3f83a12e6636

STIX ID: report--e39cccb6-d869-579f-933f-3f83a12e6636

Feed Name: The Cyber Express

Threat Score
75/100

Date Published: 2026-07-27

Date Updated: 2026-07-27

Author: Ashish Khaitan

...
...

A researcher disclosed a remote code execution vulnerability in GitLab that chains two memory-safety flaws in the Ruby Oj JSON parser used by the ipynbdiff gem when processing Jupyter Notebook (.ipynb) diffs. The exploit allows an authenticated user with push and diff-view permissions to execute arbitrary commands as the git system user, potentially exposing repository source, Rails secrets, service credentials, and internal services; affected GitLab CE/EE and Oj gem versions are listed and fixes are available — self-managed instances should upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.