GitLab 18.11.3 PoC lets authenticated users run commands via git
Source headline: Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
Intelligence Summary
A proof-of-concept published by depthfirst demonstrates a remote code execution flaw in self-managed GitLab 18.11.3. An authenticated user can trigger the issue by committing two crafted Jupyter notebooks and requesting a diff. The exploit results in command execution under the git user, without needing admin rights or CI runner access. The chain is designed to work with minimal victim interaction, increasing practical risk for misconfigured or unpatched instances. GitLab operators should check for the relevant patch/mitigation and restrict access to diff functionality where possible.
Recommended Action
Prioritize immediate review, validate exposure, and patch or mitigate affected systems.