Aikido: GitLab's secret issue email grants account-wide access
Aikido Security found that GitLab's secret email address for creating issues embeds a single account-wide PAT prefixed with "glimt-". Anyone who knows the address can create issues and merge requests, push code and run CI/CD jobs across the account's projects, bypassing IP restrictions. GitLab calls the behavior intended and offers no way to disable the feature.
- The glimt- token is identical across all projects in an account
- The email can open merge requests and run attacker code in CI/CD
- Account IP restrictions do not apply to the email channel
- Aikido found dozens of leaked addresses, including wget2's
Read next
Security