CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3209

As cited

Copy frozen at (site build).

vulnerabilities

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

A researcher released a working proof-of-concept exploit for an unpatched GitLab vulnerability (CVE-18.11.3) that allows authenticated users to execute arbitrary commands with git privileges. The attack requires only two malicious Jupyter notebook commits and a diff request, with no need for administrator rights or CI runner access.

Why it matters: Self-managed GitLab administrators must patch immediately; any authenticated user on an unpatched 18.11.3 instance can escalate to git-level command execution without additional privileges or user interaction.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

A researcher released a working proof-of-concept exploit for an unpatched GitLab vulnerability (CVE-18.11.3) that allows authenticated users to execute arbitrary commands with git privileges. The attack requires only two malicious Jupyter notebook commits and a diff request, with no need for administrator rights or CI runner access.

Why it matters: Self-managed GitLab administrators must patch immediately; any authenticated user on an unpatched 18.11.3 instance can escalate to git-level command execution without additional privileges or user interaction.

VendorsGitLab
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary