Back to all news
Security

A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You

The Hacker News·September 23, 2026·1 min read
A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You

A leaked GitLab issue email address is a credential that lets anyone push code and run CI jobs as the user. The private email, shown behind a button labeled 'Email work item to this project,' allows attackers to email a patch that GitLab commits in the victim's name to any branch, including main, and start CI/CD jobs. This poses a serious supply-chain risk.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store