Black & White Path
Jul 27, 2026 · Information Security
GitLab RCE: Authenticated Users Achieve Root via Malicious Notebook – PoC Available
Depthfirst disclosed a high‑severity GitLab vulnerability where any authenticated user can execute arbitrary commands as the git system user by pushing a crafted Jupyter notebook, leveraging two memory‑corruption bugs in the Oj gem, with a full PoC released for affected versions.
GitLabOj gemRCE
0 likes · 12 min read
