← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 25, 2026 · 15:05via CSO Online

GitLab issue email’s only security is obscurity

Brief

It was meant to make life simpler: a secret email address to which developers can send a message and create an issue in their GitLab project. But poor security defaults and a long-lived token embedded in the address mean that anyone who knows the address can potentially modify protected repositories. If project owners publish or leak these addresses, as some have, then they become vulnerable.

The project-scoped email address supplied by GitLab in the form of a button that says “Email work item to this project” can unlock account-wide access on private as well as public projects, in addition to its intended function, Aikido Security has found. The feature is turned on for every account on GitLab. com, and cannot be turned off; it may also be turned on for self-hosted instances of GitLab.

Read more on CSO Online→