SECURITYTHE HACKER NEWS
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
Security researcher Yuhang Wu at depthfirst published a proof-of-concept exploit for a GitLab vulnerability that allows authenticated users to execute commands as 'git' on unpatched self-managed GitLab 18.11.3 servers. The exploit involves committing two crafted Jupyter notebooks and requesting their diff, requiring no administrator rights or victim interaction.
Mentioned
Related Signal
Adjacent reporting
- Researchers Discover Critical GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git Push
- Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code
- No fix yet for critical RCE bug in open-source Git service Gogs - exploit module is out
- GitHub fixes RCE flaw that gave access to millions of private repos
- GitHub RCE Vulnerability: CVE-2026-3854 Breakdown