All coverage
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
🔹 The Hacker News Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git Security researcher Yuhang Wu at depthfirst has published a working proof-of-concept (PoC) exploit that executes commands as git on an unpatched self-managed GitLab 18.11.3 server. An ordinary authenticated user triggers it by committing two crafted Jupyter notebooks and requesting their diff. Th
Security researchers reported several high-severity remote code execution threats in widely used enterprise software, including Alibaba's Fastjson 1.x Java JSON library, self-managed GitLab 18.11.3 servers, and internet-exposed PTC Windchill and FlexPLM deployments [thehackernews.com#1][thehackernews.com#2][thehackernews.com#3][cybersecuritynews.com#1]. The Fastjson flaw, tracked as CVE-2026-16723
🔹 The Hacker News Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on June 10. It runs commands as git on any self-managed 18.11.3 server that has not taken the update. Any authenticated user who can push to a project can run it.
🤖 GitLab RCE PoC published: working exploit for self-managed GitLab 18.11.3. Authenticated users execute commands as git via crafted Jupyter notebook commits. Patch available since June 10 — update if not done. 🔗 https:// thehackernews.com/2026/07/rese archer-publishes-gitlab-rce-poc.html # Exploit # GitLab # RCE # CyberSec
🤖 GitLab RCE PoC published: depthfirst researchers released working exploit code for a GitLab flaw (patched June 10). Any authenticated user who can push to a project can run commands as git on unpatched self-managed 18.11.3 servers. 🔗 https:// thehackernews.com/2026/07/rese archer-publishes-gitlab-rce-poc.html # Exploit # GitLab # RCE # CyberSec
⚠️ CRITICAL: Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git A public PoC exploit now exists for a critical RCE vulnerability affecting self-managed GitLab instances. Any authenticated user can execute arbitrary commands as the 'git' system user by uploading malicious Jupyter notebooks and requesting diffs. Many instances remain vulnerable because the underl… ht
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git https:// thehackernews.com/2026/07/rese archer-publishes-gitlab-rce-poc.html