Researchers disclosed a remote code execution chain affecting default self-managed GitLab installations by exploiting two memory-safety flaws in the Ruby JSON parser Oj during Jupyter Notebook diff processing. The issue became reachable through GitLab’s handling of .ipynb files via the ipynbdiff component, allowing an authenticated user with permission to push commits and view diffs to upload crafted notebook files and execute arbitrary shell commands as the git user without administrator privileges or user interaction.
The exploit combined a one-byte memory overwrite with a heap information leak to bypass ASLR, corrupt parser state, and redirect execution to system(), aided by Puma thread reuse of the vulnerable parser instance. Researchers said successful compromise could expose source code, Rails secrets, service credentials, and internal services, creating opportunities for data theft, code tampering, and lateral movement. GitLab released fixes for CE/EE versions 18.10.8, 18.11.5, and 19.0.2, while Oj 3.17.3 patched the underlying library flaws; GitLab.com had already been updated before disclosure, and public proof-of-concept code has increased risk for unpatched deployments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Public proof-of-concept exploit code was released after disclosure, increasing the risk to unpatched self-managed GitLab deployments.
GitLab.com was already updated ahead of the public disclosure, reducing exposure for the hosted service before details of the exploit chain became public.
GitLab patched supported affected versions, including CE/EE releases 18.10.8, 18.11.5, and 19.0.2, to block exploitation of the Oj-based notebook diff attack path.
The Oj project fixed the underlying memory-safety issues in release 3.17.3, addressing the parser flaws used in the GitLab exploit chain.
Researchers disclosed an exploit chain that combines two memory corruption vulnerabilities in the Oj JSON parser to achieve remote code execution on default self-managed GitLab installations. The attack lets an authenticated user execute arbitrary shell commands as the git user without administrator privileges or user interaction.
The exploit path became reachable in GitLab 15.2.0 when Jupyter Notebook (.ipynb) files began being processed through the vulnerable Oj-based notebook diff functionality, enabling authenticated users with commit and diff-view permissions to target default self-managed installations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcethecyberexpress.com
Open sourcethecybersecguru.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.