← Back to Feed

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

July 25, 2026 · The Hacker News · Severity: HIGH

Security researchers published working exploit code for a GitLab RCE vulnerability (patched June 10, 2026) that lets any authenticated user who can push to a project run commands as the git user on self-managed GitLab 18.11.3 servers. The exploit uses crafted Jupyter notebooks to leak heap pointers via commit diffs, then fires payloads through memory corruption bugs in the Oj Ruby JSON parser. GitLab did not flag the fix as a security fix, so administrators who triaged against the security table had no reason to treat it as urgent.

Key Takeaways

  • GitLab RCE exploit lets any authenticated user with push access run commands as git on unpatched servers.
  • Exploit chain uses crafted Jupyter notebooks to leak heap pointers via commit diffs, then exploits Oj JSON parser memory corruption.
  • Self-managed GitLab 18.11.3 servers that haven't taken the June 10 patch are vulnerable with no admin rights or victim interaction required. GitLab patched the vulnerability on June 10, 2026 but did not classify it as a security fix no CVE or CVSS assigned.
☕ Buy a Coffee