{"id":5169,"date":"2026-09-26T00:32:07","date_gmt":"2026-09-26T00:32:07","guid":{"rendered":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/2026\/09\/26\/leaked-gitlab-email-tokens-can-reach-code-secrets-and-ci-cd-pipelines\/"},"modified":"2026-09-26T00:32:07","modified_gmt":"2026-09-26T00:32:07","slug":"leaked-gitlab-email-tokens-can-reach-code-secrets-and-ci-cd-pipelines","status":"publish","type":"post","link":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/2026\/09\/26\/leaked-gitlab-email-tokens-can-reach-code-secrets-and-ci-cd-pipelines\/","title":{"rendered":"Leaked GitLab Email Tokens Can Reach Code, Secrets and CI\/CD Pipelines"},"content":{"rendered":"<div><img data-opt-id=300633027  fetchpriority=\"high\" decoding=\"async\" width=\"770\" height=\"330\" src=\"https:\/\/devops.com\/wp-content\/uploads\/2026\/09\/email_tokens_security.jpg\" class=\"attachment-large size-large wp-post-image\" alt=\"\" \/><\/div>\n<p><img data-opt-id=549413439  fetchpriority=\"high\" decoding=\"async\" width=\"150\" height=\"150\" src=\"https:\/\/devops.com\/wp-content\/uploads\/2026\/09\/email_tokens_security-150x150.jpg\" class=\"attachment-thumbnail size-thumbnail wp-post-image\" alt=\"\" \/><\/p>\n<p>Security researchers have uncovered a GitLab behavior that could let attackers use a leaked project email address to push code, trigger CI\/CD jobs and reach other repositories accessible to the address owner.<\/p>\n<p>Aikido Security researcher Joe Leon detailed the attack path this week in a <a href=\"https:\/\/www.aikido.dev\/blog\/gitlab-email-push-to-main\">blog post<\/a> after reporting it to GitLab earlier this year. The issue involves GitLab\u2019s incoming email token, a credential embedded in private email addresses that GitLab provides for creating issues and merge requests by email.<\/p>\n<p>\u201cThe token inside this email address is essentially a fine-grained personal access token with significant access to your GitLab projects,\u201d the report said.<\/p>\n<p>GitLab\u2019s documentation says the token never expires and warns that anyone who obtains it can create issues and merge requests as the user. GitLab also allows users to attach .patch files when creating merge requests by email. GitLab applies the patches to the named source branch or creates the branch if it does not already exist.<\/p>\n<p>Aikido found that the same incoming email token appeared in addresses generated for different projects belonging to one user. The researchers said an attacker who obtained one of those addresses could change its suffix from -issue to -merge-request, attach a patch and submit code using the victim\u2019s existing GitLab permissions.<\/p>\n<p>The same mechanism can also turn a leaked email token into a path for CI\/CD execution. Aikido demonstrated adding a job to .gitlab-ci.yml via an emailed patch, causing GitLab to run a pipeline as the victim. Aikido also showed how to use the same access to exfiltrate private source code, read CI\/CD variables and secrets, and use a job\u2019s CI_JOB_TOKEN to access additional GitLab resources permitted to that job token.<\/p>\n<p>The attack is constrained by the victim\u2019s existing GitLab permissions and by the attacker\u2019s knowledge of the target project. The incoming email token does not elevate privileges. Aikido said an address tied to a Guest account would have little value for these attack paths, while one tied to a Maintainer could potentially expose protected branches and CI\/CD variables, depending on the project\u2019s configuration. Reaching another project also requires its project path and ID. GitLab exposes both for public projects, but going after a private project would require the attacker to obtain identifying information about it through another leak.<\/p>\n<p>Aikido reported the behavior through HackerOne in May and said the report was initially closed as intended behavior. Aikido said it filed a confidential GitLab issue in June, after which GitLab updated its interface and <a href=\"https:\/\/docs.gitlab.com\/security\/tokens\/\">documentation<\/a>. A GitLab merge request opened July 28 said previous descriptions of the token were inconsistent and updated them to more accurately explain its capabilities and emphasize that the token should remain private.<\/p>\n<p>So far, GitLab has responded by making the token\u2019s capabilities and risks clearer but has not disabled the underlying email functionality. Users who believe one of these addresses has been exposed can reset the token from GitLab\u2019s personal access token settings, which invalidates addresses containing the previous token. For organizations that rely on email-created issues or merge requests, the disclosure is a reminder that exposing those addresses can allow actions under the account owner\u2019s existing GitLab privileges.<\/p>\n<p><a href=\"https:\/\/devops.com\/leaked-gitlab-email-tokens-can-reach-code-secrets-and-ci-cd-pipelines\/\" target=\"_blank\" class=\"feedzy-rss-link-icon\">Read More<\/a><\/p>\n<p>\u200b<\/p>","protected":false},"excerpt":{"rendered":"<p>Security researchers have uncovered a GitLab behavior that could let attackers use a leaked project email address to push code, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":5170,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[5],"tags":[],"class_list":["post-5169","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-devops"],"_links":{"self":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts\/5169","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/comments?post=5169"}],"version-history":[{"count":0,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts\/5169\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/media\/5170"}],"wp:attachment":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/media?parent=5169"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/categories?post=5169"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/tags?post=5169"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}