CuraSec

Plan active

GitLab Issue Email Address Is a Credential That Can Push Code and Trigger CI

2026-09-24 15:49 UTC · The Hacker News · read the source ↗ #gitlab#ci-cd#credential-exposure
  • Engineer — Plan: If your team uses GitLab’s email-to-issue feature, those per-project addresses are live credentials — audit whether any have appeared in screenshots, bug reports, logs, or Slack, and rotate them via GitLab profile settings; also evaluate whether to disable the feature organization-wide if it isn’t actively used.
  • SOC/IR — Learn: No exploitation evidence or IOCs, but this expands the CI/CD abuse surface worth knowing for future hunts — an attacker who obtains one of these addresses could trigger pipeline jobs without touching a keyboard in a way most SIEM rules wouldn’t catch.
  • Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.