Back to Intel

Intel Node

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

mediumvulnerability2026-07-25T08:34:15+00:00source excerpt
vulnerabilityexploitation

Source excerpt · The upstream feed supplied only part of this article.Read the original source →

Security researcher Yuhang Wu at depthfirst has published a working proof-of-concept (PoC) exploit that executes commands as git on an unpatched self-managed GitLab 18.11.3 server. An ordinary authenticated user triggers it by committing two crafted Jupyter notebooks and requesting their diff.

Read Original Source