ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
CRITICAL Vulnerabilities

GitLab 18.11.3 PoC lets authenticated users run commands via git

Source headline: Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

Threat level Critical
Signal strength 75/100
Source confidence 1 source
Published 4 hours ago

Intelligence Summary

A proof-of-concept published by depthfirst demonstrates a remote code execution flaw in self-managed GitLab 18.11.3. An authenticated user can trigger the issue by committing two crafted Jupyter notebooks and requesting a diff. The exploit results in command execution under the git user, without needing admin rights or CI runner access. The chain is designed to work with minimal victim interaction, increasing practical risk for misconfigured or unpatched instances. GitLab operators should check for the relevant patch/mitigation and restrict access to diff functionality where possible.

Recommended Action

Prioritize immediate review, validate exposure, and patch or mitigate affected systems.

Topics

#rce #proof-of-concept #gitlab #authenticated-user #jupyter-notebooks
Original reporting The Hacker News Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
Open original source