Back to all news
Security

Exposed GitLab project email addresses let attackers push code

BleepingComputer·September 24, 2026·1 min read
Exposed GitLab project email addresses let attackers push code

Attackers can push code to GitLab projects by exploiting private email addresses that are deliberately exposed in READMEs, contributing guides, and support pages. These addresses allow developers to submit issues or tasks, but when publicized, they enable unauthorized code pushes. The exposure poses a security risk to projects relying on these email-based workflows.

Read at BleepingComputer
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store