Aikido researchers found private GitLab incoming email addresses exposed in public READMEs, contributing guides, and support pages, creating a risk that attackers could abuse them to create issues, merge requests, or gain broader access. GitLab says these addresses are private and should be reset if leaked, while maintainers are urged to stop publishing them and review projects that exposed them. #GitLab #Aikido
Keypoints
- Private GitLab incoming email addresses were found exposed in public project documentation.
- Each address contains a long-lived token tied to the developerβs account.
- An attacker could change the suffix to create merge requests instead of issues.
- The attack may bypass IP restrictions and expose code, secrets, and private issues.
- Project maintainers should remove exposed addresses and reset leaked tokens immediately.