hacker-news · Crawled Jul 25, 2026

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

1 IoCs
Read original article ↗

AI Summary

A security researcher published a proof-of-concept exploit for a critical remote code execution (RCE) vulnerability in GitLab, affecting self-managed instances from versions 15.2.0 to 19.0.1. The vulnerability allows authenticated users to execute arbitrary commands as the 'git' user by exploiting memory corruption bugs in the Oj Ruby JSON parser via crafted Jupyter notebooks. Despite being patched in June 2026, the fix was not classified as a security update, leading to potential under-prioritization by administrators. No CVE has been assigned, and exploitation in the wild has not been observed.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
Package Oj 3.17.1 Details →