Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git 7%

By Swati Khandelwal11%

7/25/2026, 3:14:00 AM

BS Summary: This article contains 19 faulty reasoning types, including Post Hoc (False Cause), Overconfidence Bias, and Actor-Observer Bias, with Availability Heuristic as the most egregious example at 14.3% saturation with 89 hits. Analysis detected 542 faulty-reasoning hits from 621 analyzed words, generating a BS Score of 23% and a BS Rank of 7% (20,459 of 21,887 articles). This article is better (less manipulative) than 93.50% of the article peer group.

Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on June 10. 
It runs commands as git on any self-managed 18.11.3 server that has not taken the update. 
Any authenticated user who can push to a project can run it. 
The attacker commits a crafted Jupyter notebook and opens its commit diff, which leaks a heap pointer. 
Enough of those and an automated probe can locate the libraries in memory. 
Two more notebooks then fire the payload. 
No administrator rights, no CI or runner access, no victim interaction, no access to anyone else's project. 
GitLab did not file the fix as a security fix. 
A review by The Hacker News found the Oj 3.17.3 bump listed under bug fixes in the June 10 patch release, not in the security-fix table. 
There is no CVE, no CVSS score, and no mention of the notebook-diff chain. 
Operators who triaged that release against the security table had no reason to treat it as urgent. 
Two memory corruption bugs in Oj, a Ruby JSON parser implemented largely in native C, make the chain work. depthfirst says its system flagged them autonomously, and researchers chained them by hand. 
GitLab's notebook renderer, an in-tree gem called ipynbdiff, passes repository-controlled .ipynb JSON to Oj::Parser.usual.parse inside a long-lived Puma worker, so attacker-controlled bytes reach Oj's manually managed C memory inside the application process. 
One bug writes past a fixed 1,024-byte nesting stack until it controls the parser's start callback. 
The other truncates a 65,565-byte object key to 29 in a signed 16-bit field and returns a live heap pointer, which GitLab renders into the diff. 
The leak locates libc, and the write points the callback at system(). 
All tiers are affected, CE and EE, Free through Ultimate. 
Ruby itself is not. 
Oj 3.17.2 carried other fixes from the same review but not these two. 
Upgrade to 18.10.8, 18.11.5, or 19.0.2. 
Neither GitLab nor depthfirst offers a workaround for anyone who cannot. 
The trap is Helm and Operator: check the GitLab version inside the Webservice image running Puma, not the chart or Operator version. 
Anything on 15.2 through 18.9 gets no backport, because those lines sit outside GitLab's security-maintained patch trains, so those installs have to move to a supported release instead. 
Commands run as git, the account behind Puma. 
How far that goes depends on how the install is isolated. 
In reach: source code, Rails secrets, service credentials, CI/CD data, and internal services the application can talk to. 
The public exploit is built for GitLab 18.11.3 on x86-64. 
Gadget offsets, register state, and jemalloc behavior all came from that image, and a recovered library base holds only until the Puma master restarts, so this is not drop-in against an arbitrary target. 
The Oj bugs are general; porting the exploit is real work. depthfirst measured five to ten minutes for the memory search on a fresh two-worker install and projects one to two hours on longer-running ones. 
Its writeup has the full chain. 
depthfirst reported the Oj bugs on May 21, the maintainer merged fixes on May 27, and Oj 3.17.3 shipped June 4. 
The GitLab chain went to GitLab on June 5, was confirmed on June 8, and was patched on June 10. depthfirst says it is not aware of in-the-wild exploitation, and that GitLab reproduced the RCE independently. 
Its wider Oj review produced nine more CVE advisories, none of them this chain. 
The Hacker News has asked GitLab why the fix was not classified as a security issue and whether a CVE will be assigned, and asked depthfirst about exploit portability. 
Responses are pending. 
Article reasoning-pattern comparisonThis article: 5.0%Swati Khandelwal: 2.4%The Hacker News: 1.9%Confirmation Bias5.0%This article: 5.3%Swati Khandelwal: 1.5%The Hacker News: 1.2%Anchoring Bias5.3%This article: 14.3%Swati Khandelwal: 3.5%The Hacker News: 3.3%Availability Heuristic14.3%This article: 3.5%Swati Khandelwal: 1.4%The Hacker News: 1.5%Representativeness Heuristic3.5%This article: 0.0%Swati Khandelwal: 0.7%The Hacker News: 0.6%Hindsight Bias0.0%This article: 6.8%Swati Khandelwal: 2.4%The Hacker News: 2.5%Overconfidence Bias6.8%This article: 2.3%Swati Khandelwal: 2.8%The Hacker News: 2.7%Framing Effect2.3%This article: 0.0%Swati Khandelwal: 0.9%The Hacker News: 1.0%Loss Aversion0.0%This article: 3.5%Swati Khandelwal: 0.7%The Hacker News: 0.6%Status Quo Bias3.5%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Sunk Cost Effect0.0%This article: 0.0%Swati Khandelwal: 1.2%The Hacker News: 1.3%Optimism Bias0.0%This article: 3.2%Swati Khandelwal: 1.9%The Hacker News: 1.6%Pessimism Bias3.2%This article: 2.9%Swati Khandelwal: 6.3%The Hacker News: 6.7%Negativity Bias2.9%This article: 0.0%Swati Khandelwal: 0.4%The Hacker News: 0.8%Self-Serving Bias0.0%This article: 0.0%Swati Khandelwal: 0.4%The Hacker News: 0.4%Fundamental Attribution Error0.0%This article: 5.8%Swati Khandelwal: 0.1%The Hacker News: 0.1%Actor-Observer Bias5.8%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%In-Group Bias0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.3%Out-Group Homogeneity Bias0.0%This article: 0.0%Swati Khandelwal: 0.4%The Hacker News: 0.6%Halo Effect0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Horn Effect0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Dunning-Kruger Effect0.0%This article: 3.4%Swati Khandelwal: 1.5%The Hacker News: 1.5%Recency Bias3.4%This article: 0.0%Swati Khandelwal: 0.2%The Hacker News: 0.3%Primacy Effect0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Blind-Spot Bias0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.1%Ad Hominem0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.1%Straw Man0.0%This article: 0.0%Swati Khandelwal: 3.9%The Hacker News: 4.0%Appeal to Authority0.0%This article: 1.8%Swati Khandelwal: 1.3%The Hacker News: 1.6%False Dilemma1.8%This article: 0.0%Swati Khandelwal: 0.7%The Hacker News: 0.5%Slippery Slope0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Circular Reasoning0.0%This article: 2.9%Swati Khandelwal: 3.8%The Hacker News: 4.3%Hasty Generalization2.9%This article: 2.3%Swati Khandelwal: 0.2%The Hacker News: 0.1%Red Herring2.3%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.2%Bandwagon0.0%This article: 0.0%Swati Khandelwal: 0.8%The Hacker News: 1.1%Appeal to Emotion0.0%This article: 0.0%Swati Khandelwal: 0.3%The Hacker News: 0.5%Begging the Question0.0%This article: 8.5%Swati Khandelwal: 2.0%The Hacker News: 1.9%Post Hoc (False Cause)8.5%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Tu Quoque0.0%This article: 2.7%Swati Khandelwal: 0.7%The Hacker News: 0.6%Burden of Proof2.7%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Appeal to Nature0.0%This article: 0.0%Swati Khandelwal: 0.3%The Hacker News: 0.3%Composition/Division0.0%This article: 0.0%Swati Khandelwal: 1.1%The Hacker News: 1.0%Anecdotal0.0%This article: 5.8%Swati Khandelwal: 0.1%The Hacker News: 0.1%No True Scotsman5.8%This article: 2.7%Swati Khandelwal: 2.5%The Hacker News: 2.3%Ambiguity (Equivocation)2.7%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Gambler’s Fallacy0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Middle Ground0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Personal Incredulity0.0%This article: 4.5%Swati Khandelwal: 0.2%The Hacker News: 0.1%Special Pleading4.5%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Genetic Fallacy0.0%This article: 0.0%Swati Khandelwal: 1.0%The Hacker News: 1.4%Unattributed Quote0.0%This article: 0.0%Swati Khandelwal: 0.8%The Hacker News: 0.9%Quote-first Misdirection0.0%This article: 0.0%Swati Khandelwal: 2.7%The Hacker News: 2.3%Biased Writer Voice0.0%This article: 0.0%Swati Khandelwal: 5.0%The Hacker News: 4.4%Indoctrination0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Politically Left Leaning Bias0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Politically Right Leaning Bias0.0%This article: 0.0%Swati Khandelwal: 0.4%The Hacker News: 3.0%Attempt to Sell a Product or S…0.0%

621 words analyzed.

Speakers

1speaker8.9%attributed speech566writer words
Voice mapSelect a segment to jump to its words
Writer's voice • 12 words • 0.0% coverageWriter's voice • 24 words • 0.0% coverageWriter's voice • 16 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 17 words • 0.0% coverageWriter's voice • 13 words • 0.0% coverageWriter's voice • 7 words • 0.0% coverageWriter's voice • 17 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageThe Hacker News • 26 words • 0.0% coverageWriter's voice • 14 words • 0.0% coverageWriter's voice • 17 words • 0.0% coverageWriter's voice • 32 words • 0.0% coverageWriter's voice • 32 words • 0.0% coverageWriter's voice • 16 words • 0.0% coverageWriter's voice • 26 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageWriter's voice • 4 words • 0.0% coverageWriter's voice • 13 words • 0.0% coverageWriter's voice • 6 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageWriter's voice • 22 words • 0.0% coverageWriter's voice • 28 words • 0.0% coverageWriter's voice • 8 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageWriter's voice • 18 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageWriter's voice • 33 words • 0.0% coverageWriter's voice • 35 words • 0.0% coverageWriter's voice • 6 words • 0.0% coverageWriter's voice • 21 words • 0.0% coverageWriter's voice • 36 words • 0.0% coverageWriter's voice • 14 words • 0.0% coverageThe Hacker News • 29 words • 0.0% coverageWriter's voice • 3 words • 0.0% coverage
Selected voice

The Hacker News

47%flagged-word coverage
55 attributed words100% of attributed speech59% writer coverage

No manipulation-pattern hits were found in this speaker's attributed words or the writer's voice.

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.