Critical GitLab RCE vulnerability chain requires patching

Researchers discovered a critical remote code execution chain in GitLab by combining two Oji parser bugs exploitable via Jupyter notebook diffs. The vulnerability affects authenticated users and urgent patches are being urged.

2 reportsother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

GitLab Users Urged to Patch After Research Reveals Critical RCE Chain

stream:bsky-jetstreamother63d ago kagi ↗

GitLab Users Urged to Patch After Research Reveals Critical RCE Chain Researchers chained two Oj parser bugs to achieve GitLab RCE via Jupyter notebook diffs, affecting authenticated users on unpatched versions. Depthfirst researchers published a working remote code execution exp… #hackernews #news Researchers chained two Oj parser bugs to achieve GitLab RCE via Jupyter notebook diffs, affecting a