The first critical remote code execution vulnerability in an AI-specific infrastructure component uses Jinja2 template injection to break out of the sandbox. Self-hosted GitLab instances are exposed; ...
CVE-2026-85706 is a critical GitLab path-traversal vulnerability that has moved beyond theoretical risk into confirmed ...
GitLab disclosed a critical flaw in its self-hosted AI Gateway on October 2, assigning it a CVSS score of 9.9 out of 10. The bug, tracked ...
GitLab has released urgent security updates for a critical AI Gateway vulnerability that could allow authenticated attackers ...
GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary ...
How much of a software engineer's day is actually spent writing code that 'creates new value'?In many workplaces, what ...
GitLab is undervalued, trading at 4–5x FY2028–29E revenue, despite robust execution and accelerating AI-driven demand. Read ...
GitLab released emergency updates for two critical flaws enabling authenticated users to execute arbitrary code via crafted ...
A GitLab feature designed to let users create work items through email can be abused as an account-level code delivery ...
Incoming email addresses automatically assigned to each user on the platform contain highly privileged access tokens that attackers can use.
GitLab’s non-expiring incoming email token can let a holder commit code with a user’s permissions and trigger CI/CD jobs.
The vulnerability impacts self-managed CE and EE instances and provides an unauthenticated path to arbitrary file reads. It’s already being probed in the wild. Yet another security vulnerability has ...