Security · 1d ago
GitLab RCE Exploit Published for Unpatched Self-Managed Servers
A researcher published a working exploit for a GitLab remote code execution flaw patched on June 10. The bug affects self-managed GitLab 18.11.3 servers that haven't updated. Any authenticated user with push access can run commands as the git user by committing a crafted Jupyter notebook and viewing its diff.
Meridian48 take
The exploit's public release raises the stakes for GitLab admins who delayed patching, as the attack surface is broad and authentication alone is no defense.
Read the full reporting
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git →
The Hacker News
gitlabrce-exploit