Dossier
Yuhang Wu
Coverage of Yuhang Wu in the Nexus archive.
- Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
Security researcher Yuhang Wu at depthfirst published a proof-of-concept exploit for a GitLab vulnerability that allows authenticated users to execute commands as 'git' on unpatched self-managed GitLab 18.11.3 servers. The exploit involves committing two crafted Jupyter notebooks and requesting their diff, requiring no administrator rights or victim interaction.