logo

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

ID: 3f454325-cc0e-54f9-a306-a819663da4cd

STIX ID: report--3f454325-cc0e-54f9-a306-a819663da4cd

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-07-25

Date Updated: 2026-07-25

Author: [email protected] (The Hacker News)

...
...

Security researchers disclosed a chain of memory-corruption bugs in the Oj Ruby JSON parser that can be exploited via GitLab's notebook-diff renderer (ipynbdiff) to achieve remote code execution as the `git` account on self-managed GitLab instances. A public proof-of-concept exploit was published after GitLab patched affected releases (multiple CE/EE versions and Oj 3.13.0–3.17.1), no CVE was assigned at publication, and operators are advised to upgrade to 18.10.8, 18.11.5, or 19.0.2 (or later) since no workaround is available for unsupported releases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.