GitLab’s incoming email address is effectively a long-lived credential that can be abused to create issues, merge requests, and even commit code as the account holder if it is leaked. Aikido Security found that the token works across all accessible projects, bypasses IP allowlists and 2FA, and can affect branches such as main when paired with GitLab’s email-based merge request feature. #GitLab #AikidoSecurity
Keypoints
- GitLab’s project email address acts as a credential tied to the user account.
- The same token works across multiple projects the account can access.
- Anyone with the address can submit emails as if they came from the account owner.
- GitLab can turn emailed patches into commits on targeted branches, including main.
- The attack can bypass IP restrictions and 2FA, depending on the user’s permissions.
Read More: https://thehackernews.com/2026/09/a-leaked-gitlab-issue-email-address.html