Toggle light / dark theme

Exposed GitLab project email addresses let attackers push code

Private GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in READMEs, contributing guides, and support pages used to collect bug reports.

The addresses are part of a built-in GitLab feature called “Email work item to this project” and contain a long-lived token tied to the developer’s account.

These addresses are generated automatically and contain a string that serves as a credential for creating work items via email. When an external client sends a message to one of them, GitLab parses it into a project issue or task.

Leave a Comment

Lifeboat Foundation respects your privacy! Your email address will not be published.

/* */