Skip to content
Tech News
← Back to articles

GitLab email-to-issue addresses leaking in public docs enable code pushes

read original get Yubico YubiKey 5C NFC Security Key → more articles
GoKawiil Brief

Aikido Security found that GitLab's built-in 'Email work item to this project' addresses, which embed a long-lived credential token, are being publicly exposed in READMEs, contributing guides, and support pages. Anyone who obtains one of these addresses can email GitLab to create issues, and by swapping the '-issue' suffix for '-merge-request,' can open merge requests as if they were the token owner, since GitLab does not verify the sender's email matches the token owner and the technique also bypasses IP restrictions.

Why It Matters

GoKawiil's interpretation of the reporting above, not reported fact.

Because access via these tokens carries the permissions of the account they belong to, exposure could let attackers push malicious code to protected branches, exfiltrate source code, harvest CI/CD secrets, or view confidential issues in private repositories. Aikido notes GitLab is only now considering adding sender-verification as a safeguard, suggesting the gap has existed without this defense until researchers flagged it. The severity for any given project depends on the compromised user's permission level.

Key Takeaways
Worth a Look

Yubico YubiKey 5C NFC Security Key — Since this GitLab exploit hinges on stolen tokens and compromised developer credentials, pairing hardware-backed two-factor authentication with your accounts adds a strong extra layer of defense. A YubiKey makes it much harder for attackers to hijack your GitLab or GitHub account even if an email token or password leaks. It's a simple, one-time purchase that strengthens your entire dev workflow security.

See Yubico YubiKey 5C NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Source: bleepingcomputer.com, 2026-09-24

Published there as: “Exposed GitLab project email addresses let attackers push code”

Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.