hacker-news · Crawled Jul 25, 2026
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
1 IoCs
Read original article ↗
AI Summary
A security researcher published a proof-of-concept exploit for a critical remote code execution (RCE) vulnerability in GitLab, affecting self-managed instances from versions 15.2.0 to 19.0.1. The vulnerability allows authenticated users to execute arbitrary commands as the 'git' user by exploiting memory corruption bugs in the Oj Ruby JSON parser via crafted Jupyter notebooks. Despite being patched in June 2026, the fix was not classified as a security update, leading to potential under-prioritization by administrators. No CVE has been assigned, and exploitation in the wild has not been observed.
AI-extracted · verify before operational use
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Package | Oj 3.17.1 | Details → |