GitLab email-to-issue addresses leaking in public docs enable code pushes
Aikido Security found that GitLab's built-in 'Email work item to this project' addresses, which embed a long-lived credential token, are being publicly exposed in READMEs, contributing guides, and support pages. Anyone who obtains one of these addresses can email GitLab to create issues, and by swapping the '-issue' suffix for '-merge-request,' can open merge requests as if they were the token owner, since GitLab does not verify the sender's email matches the token owner and the technique also bypasses IP restrictions.
GoKawiil's interpretation of the reporting above, not reported fact.
Because access via these tokens carries the permissions of the account they belong to, exposure could let attackers push malicious code to protected branches, exfiltrate source code, harvest CI/CD secrets, or view confidential issues in private repositories. Aikido notes GitLab is only now considering adding sender-verification as a safeguard, suggesting the gap has existed without this defense until researchers flagged it. The severity for any given project depends on the compromised user's permission level.
- GitLab's email-to-issue addresses contain persistent 'glimt-' tokens that function as credentials.
- Changing the email suffix from '-issue' to '-merge-request' lets attackers open merge requests using someone else's token.
- GitLab does not verify sender identity or enforce IP restrictions on these addresses, and is only now considering fixes.
Yubico YubiKey 5C NFC Security Key — Since this GitLab exploit hinges on stolen tokens and compromised developer credentials, pairing hardware-backed two-factor authentication with your accounts adds a strong extra layer of defense. A YubiKey makes it much harder for attackers to hijack your GitLab or GitHub account even if an email token or password leaks. It's a simple, one-time purchase that strengthens your entire dev workflow security.
See Yubico YubiKey 5C NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.Source: bleepingcomputer.com, 2026-09-24
Published there as: “Exposed GitLab project email addresses let attackers push code”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.