#GitLab
All CosmicBytez Labs articles tagged #GitLab, across news, security advisories, how-to guides, and projects.
- News
GitLab Email Addresses Can Be Weaponized for Supply Chain Attacks
Aikido Security: GitLab's incoming-email address embeds an account-wide token letting attackers push code, run CI jobs, and bypass IP allowlists and 2FA.
- Security
Critical SSRF in GitLab MCP Server Leaks Private Tokens to Attackers
CVE-2026-61559 lets attackers redirect @zereight/mcp-gitlab's outbound API calls via a request header, leaking victim GitLab tokens to attacker hosts.
- Security
GitLab MCP Server Open to DNS Rebinding, Full Account Takeover
CVE-2026-61568 (CVSS 9.6) lets a malicious webpage use DNS rebinding to reach a victim's local GitLab MCP server and hijack their GitLab account.
- Newsletter
Weekly Digest — Issue #35
Cisco's email gateway gets root-RCE'd via crafted SQL, GitLab ships a perfect 10.0 path traversal, and China chains three zero-days to backdoor NGOs.
- News
Maximum Severity GitLab Flaw Puts Supply Chains at Risk
CVE-2026-85706 (CVSS 10.0) lets unauthenticated attackers read arbitrary files via GitLab's commits API. Already actively exploited.
- News
GitLab's CVSS 10 File-Read Flaw Draws Probes Within Hours of Disclosure
CVE-2026-85706, a CVSS 10 GitLab path traversal, hit CISA's KEV catalog after watchTowr spotted active probing the same day it was patched.
- Security
GitLab EE Patches CVSS 9.9 Duo Chat Flaw Exposing Search Credentials
A crafted GraphQL subscription lets an authenticated Duo Chat user bypass serialization and steal Advanced Search credentials in GitLab EE.
- Security
CVE-2026-85706: GitLab Path Traversal Flaw Hit CVSS 10.0, Added to CISA KEV
Unauthenticated attackers can read arbitrary files via GitLab's commits API. Exploited a day after disclosure; now in CISA's KEV catalog.
- Security
CVE-2026-10053: GitLab CE/EE Path Traversal Enables Remote Code Execution
A path traversal flaw in GitLab's package registry allows authenticated users to achieve RCE. Affects versions 18.8 through 19.2.1.
- News
Critical GitLab GraphQL Flaw Lets Unauthenticated Attackers Delete Public Projects
CVE-2026-19478 (CVSS 9.4) lets unauthenticated attackers delete public GitLab projects via GraphQL. Self-managed CE/EE must patch to 19.2.4 immediately.
- News
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
Security researcher Yuhang Wu published a working PoC exploiting two Ruby memory corruption vulnerabilities in the Oj JSON parser to achieve RCE as the...
- Security
CVE-2026-10087: GitLab EE Stored XSS via Developer Role
GitLab EE versions 17.1 through 19.x are affected by a stored cross-site scripting vulnerability (CVSS 8.7) that allows an authenticated developer to...
- Security
CVE-2026-2370: GitLab Jira Connect Credential Impersonation
GitLab has patched a high-severity vulnerability in its Jira Connect integration affecting CE/EE versions from 14.3 through 18.10 that allowed an...
- Security
CISA Adds Four Critical Vulnerabilities to KEV Catalog
CISA has updated the Known Exploited Vulnerabilities catalog with four actively exploited flaws including Microsoft Office and SmarterMail vulnerabilities.