Skip to content
The Nexus
SECURITYJul 25 · 08:34 UTCTHE HACKER NEWS[email protected] (The Hacker News)

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

Security researcher Yuhang Wu at depthfirst published a proof-of-concept exploit for a GitLab vulnerability that allows authenticated users to execute commands as 'git' on unpatched self-managed GitLab 18.11.3 servers. The exploit involves committing two crafted Jupyter notebooks and requesting their diff, requiring no administrator rights or victim interaction.

Nexus surfaces and summarizes. The full story lives at the source.

Mentioned
Spot something wrong with this article?Report a problem →
Forward this
Related Signal

Adjacent reporting

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git · The Nexus