Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Review: Shiva Naipaul’s ‘Journey to Nowhere’ Tries to Put Guyana Back Into the Jonestown Story

    July 25, 2026

    Scrutiny of WNBA intensifies as disarray looms over All-Star festivities | Basketball News

    July 25, 2026

    Can Japan avoid a Liz Truss-style shock as its PM embarks on a giant spending spree? | Japan

    July 25, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Review: Shiva Naipaul’s ‘Journey to Nowhere’ Tries to Put Guyana Back Into the Jonestown Story
    • Scrutiny of WNBA intensifies as disarray looms over All-Star festivities | Basketball News
    • Can Japan avoid a Liz Truss-style shock as its PM embarks on a giant spending spree? | Japan
    • TechCrunch Disrupt 2026’s new Smart Money Stage explores fintech, payments, AI, and everything between 
    • CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking
    • These 10 altcoins are still worth $12B after a 97% collapse
    • Riding the Greenland Ferry
    • ‘The dogs were getting upset’: How LA band Muna survived their worst ever gig
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, July 25
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 25, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalJul 25, 2026Vulnerability / Application Security

    Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on June 10. It runs commands as git on any self-managed 18.11.3 server that has not taken the update.

    Any authenticated user who can push to a project can run it. The attacker commits a crafted Jupyter notebook and opens its commit diff, which leaks a heap pointer. Enough of those and an automated probe can locate the libraries in memory. Two more notebooks then fire the payload. No administrator rights, no CI or runner access, no victim interaction, no access to anyone else’s project.

    GitLab did not file the fix as a security fix. A review by The Hacker News found the Oj 3.17.3 bump listed under bug fixes in the June 10 patch release, not in the security-fix table. There is no CVE, no CVSS score, and no mention of the notebook-diff chain. Operators who triaged that release against the security table had no reason to treat it as urgent.

    Cybersecurity

    Two memory corruption bugs in Oj, a Ruby JSON parser implemented largely in native C, make the chain work. depthfirst says its system flagged them autonomously, and researchers chained them by hand.

    GitLab’s notebook renderer, an in-tree gem called ipynbdiff, passes repository-controlled .ipynb JSON to Oj::Parser.usual.parse inside a long-lived Puma worker, so attacker-controlled bytes reach Oj’s manually managed C memory inside the application process.

    One bug writes past a fixed 1,024-byte nesting stack until it controls the parser’s start callback. The other truncates a 65,565-byte object key to 29 in a signed 16-bit field and returns a live heap pointer, which GitLab renders into the diff. The leak locates libc, and the write points the callback at system().

    Component Affected First fixed
    GitLab CE/EE 15.2.0 to 18.10.7 18.10.8
    GitLab CE/EE 18.11.0 to 18.11.4 18.11.5
    GitLab CE/EE 19.0.0 to 19.0.1 19.0.2
    Oj gem 3.13.0 to 3.17.1 3.17.3

    All tiers are affected, CE and EE, Free through Ultimate. Ruby itself is not. Oj 3.17.2 carried other fixes from the same review but not these two.

    Upgrade to 18.10.8, 18.11.5, or 19.0.2. Neither GitLab nor depthfirst offers a workaround for anyone who cannot.

    The trap is Helm and Operator: check the GitLab version inside the Webservice image running Puma, not the chart or Operator version. Anything on 15.2 through 18.9 gets no backport, because those lines sit outside GitLab’s security-maintained patch trains, so those installs have to move to a supported release instead.

    Commands run as git, the account behind Puma. How far that goes depends on how the install is isolated. In reach: source code, Rails secrets, service credentials, CI/CD data, and internal services the application can talk to.

    The public exploit is built for GitLab 18.11.3 on x86-64. Gadget offsets, register state, and jemalloc behavior all came from that image, and a recovered library base holds only until the Puma master restarts, so this is not drop-in against an arbitrary target.

    Cybersecurity

    The Oj bugs are general; porting the exploit is real work. depthfirst measured five to ten minutes for the memory search on a fresh two-worker install and projects one to two hours on longer-running ones. Its writeup has the full chain.

    depthfirst reported the Oj bugs on May 21, the maintainer merged fixes on May 27, and Oj 3.17.3 shipped June 4. The GitLab chain went to GitLab on June 5, was confirmed on June 8, and was patched on June 10. depthfirst says it is not aware of in-the-wild exploitation, and that GitLab reproduced the RCE independently. Its wider Oj review produced nine more CVE advisories, none of them this chain.

    The Hacker News has asked GitLab why the fix was not classified as a security issue and whether a CVE will be assigned, and asked depthfirst about exploit portability. Responses are pending.

    Authenticated Commands Git GitLab Letting PoC publishes RCE Researcher Run users
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

    Europol flags 4,340 URLs for removal in ‘The Com’ crackdown

    Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack

    Strategy now publishes the Bitcoin return threshold below which it may have to restructure

    Microsoft blames massive Microsoft 365 outage on maintenance bug

    NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Review: Shiva Naipaul’s ‘Journey to Nowhere’ Tries to Put Guyana Back Into the Jonestown Story

    July 25, 2026

    Scrutiny of WNBA intensifies as disarray looms over All-Star festivities | Basketball News

    July 25, 2026

    Can Japan avoid a Liz Truss-style shock as its PM embarks on a giant spending spree? | Japan

    July 25, 2026

    TechCrunch Disrupt 2026’s new Smart Money Stage explores fintech, payments, AI, and everything between 

    July 25, 2026
    Latest Posts

    Trump slaps 50% tariffs on Canada and Carney vows to ‘intensify’ trade talks

    July 21, 2026

    How Two Brothers Dug for Dead Relatives: With a Shovel and a Kitchen Knife

    July 21, 2026

    Chile floods: Towns evacuated following heavy rain in Coquimbo

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Review: Shiva Naipaul’s ‘Journey to Nowhere’ Tries to Put Guyana Back Into the Jonestown Story

    July 25, 2026

    Scrutiny of WNBA intensifies as disarray looms over All-Star festivities | Basketball News

    July 25, 2026

    Can Japan avoid a Liz Truss-style shock as its PM embarks on a giant spending spree? | Japan

    July 25, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.