Follow the latest coverage, related explainers and connected technology stories.
Aikido warned that email addresses for the GitLab feature that sends work items to projects are sometimes published in public documentation, potentially allowing attackers to create issues and merge requests with the victim account’s permissions. Depending on the account’s privileges, this could enable code modification, CI/CD job execution, or access to private repositories and secrets.