Aikido Security reported that GitLab's “Email work item to this project” addresses contain a long-lived, account-wide glimt- incoming-email token. An attacker who obtains one of these addresses can submit email as the token owner, create work items and merge requests, and send Git patches for application to repository branches—potentially affecting private projects under that user's permissions. The same token is reportedly embedded in addresses generated for multiple projects and is non-expiring.
A malicious patch modifying .gitlab-ci.yml could trigger attacker-controlled CI/CD jobs and expose source code or secrets; a leaked Maintainer token could also enable changes to protected branches. The inbound-email workflow reportedly bypasses project IP restrictions and does not validate sender addresses. GitLab has characterized the behavior as designed and updated interface wording and documentation, but has not changed the account-wide token model or added granular controls to disable the affected email features.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Aikido researcher Joe Leon published research showing that exposed, long-lived GitLab incoming-email addresses can be used under the token owner's permissions to create merge requests and apply emailed patches. The research reported potential commits to protected branches, CI/CD execution and secret exposure, and bypass of project IP restrictions where permissions allow.
After the HackerOne report was closed, the researchers filed a confidential issue directly with GitLab concerning the incoming-email token behavior.
Aikido Security researchers reported GitLab's account-wide incoming-email token behavior through HackerOne, where the report was closed as intended behavior.
GitLab opened an issue to explore verifying that incoming work-item messages originate from an email address associated with the token owner's account.
Following disclosure, GitLab removed interface wording that suggested the token could not access other data and clarified documentation on merge-request use, token secrecy and resets, and the exemption from project IP restrictions. The underlying account-wide incoming-email mechanism was not changed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.