Aikido Security finds GitLab issue-creation email addresses can grant account-level access
Aikido Security published research showing that GitLab's per-user incoming email address, meant to let users create project issues via email, contains a non-expiring token that functions as an authentication and authorization credential. Because GitLab treats any message sent to that address as coming from its owner, exposure of the address alone can let an attacker create issues, submit merge requests, or send patch files across an organization's public and private projects without needing account credentials.
GoKawiil's interpretation of the reporting above, not reported fact.
If exposed addresses are being abused, attackers could inject malicious code or requests into software projects, raising supply chain risk for organizations relying on GitLab. Aikido's researchers suggest the scope of this risk is poorly understood by users partly because GitLab's interface does not clearly flag how privileged these addresses are, though GitLab has not been quoted confirming that assessment.
- GitLab's per-user email addresses carry non-expiring tokens granting broad account-level access.
- Publicly exposed addresses could let attackers create issues or submit code changes without login credentials.
- Aikido Security warns many users underestimate this risk, partly due to unclear UI messaging.
Source: darkreading.com — Rob Wright, 2026-09-23
Published there as: “GitLab Email Addresses Can Be Weaponized for Supply Chain Attacks”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.