GitLab RCE: Authenticated Users Achieve Root via Malicious Notebook – PoC Available
Depthfirst disclosed a high‑severity GitLab vulnerability where any authenticated user can execute arbitrary commands as the git system user by pushing a crafted Jupyter notebook, leveraging two memory‑corruption bugs in the Oj gem, with a full PoC released for affected versions.
