RT by @TheHackersNews: 🚨 A public GitLab RCE PoC lets an authenticated user run commands as the git user on an unpatched 18.11.3 server. No admin rights, CI runner access, victim interaction, or access to another user’s project. See how the notebook-diff chain works: https://thehackernews.com/2026/07/researcher-publishes-gitlab-rce-poc.html
<p>🚨 A public GitLab RCE PoC lets an authenticated user run commands as the git user on an unpatched 18.11.3 server.<br /> <br /> No admin rights, CI runner access, victim interaction, or access to another user’s project.<br /> <br /> See how the notebook-diff chain works: <a href="https://thehackernews.com/2026/07/researcher-publishes-gitlab-rce-poc.html">thehackernews.com/2026/07/re…</a></p> <video loop="loop" poster="https://nitter.net/pic/tweet_video_thumb%2FHOD4HzibsAAbkpa.jpg"> <source src="https://nitter.net/pic/video.twimg.com%2Ftweet_video%2FHOD4HzibsAAbkpa.mp4" type="video/mp4" /><