Bleepingcomputer iconBleepingcomputerSep 24, 2026

Exposed GitLab project email addresses let attackers push code

Private GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in READMEs, contributing guides, and support pages used to collect bug reports.

Exposed GitLab project email addresses let attackers push code

Share this story

Send the public story page.

Useful takeaways from this story.

Private GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in READMEs, contributing guides, and support pages used to collect bug reports.

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

Private GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in READMEs, contributing guides, and support pages used to collect bug reports.

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app