Exposed GitLab project email addresses let attackers push code
Aikido warns published GitLab incoming-email tokens can let outsiders open merge requests and push code as the owner.
Aikido found private GitLab addresses for the "Email work item to this project" feature published in READMEs, contributing guides, and support pages. Each address embeds a long-lived glimt- token, and changing the suffix from issue to merge-request can open a merge request as the token owner without GitLab checking the sender address. Resulting access follows that user's permissions and may include code changes, CI/CD runs, private repositories, and secrets; IP restrictions are also bypassed. GitLab initially closed Aikido's May HackerOne report as intended behavior, then updated its interface and documentation. Exposed tokens should be reset.