Skip to content
Tech News
← Back to articles

Aikido Security finds GitLab issue-creation email addresses can grant account-level access

read original more articles
GoKawiil Brief

Aikido Security published research showing that GitLab's per-user incoming email address, meant to let users create project issues via email, contains a non-expiring token that functions as an authentication and authorization credential. Because GitLab treats any message sent to that address as coming from its owner, exposure of the address alone can let an attacker create issues, submit merge requests, or send patch files across an organization's public and private projects without needing account credentials.

Why It Matters

GoKawiil's interpretation of the reporting above, not reported fact.

If exposed addresses are being abused, attackers could inject malicious code or requests into software projects, raising supply chain risk for organizations relying on GitLab. Aikido's researchers suggest the scope of this risk is poorly understood by users partly because GitLab's interface does not clearly flag how privileged these addresses are, though GitLab has not been quoted confirming that assessment.

Key Takeaways

Source: darkreading.com — Rob Wright, 2026-09-23

Published there as: “GitLab Email Addresses Can Be Weaponized for Supply Chain Attacks”

Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.