The "Email work item to this project" feature in GitLab can be exploited, according to research by Aikido Security researcher Joe Leon on September 23, 2026 This article explores gitlab exploited according. . This flaw extends beyond just issue spam, as addresses for different projects contain the same token, making it easy for malicious actors to impersonate other users and create unauthorized work items.

The research revealed that GitLab allowed an unrelated IP address to be accepted, while blocking browser access and Git cloning but accepted an email patch, committing it to the main branch. GitLab now explicitly states that incoming emails are not subject to IP restrictions, indicating that allowlists do not fully define security boundaries for these workflows.

Updated interface and documentation now mention both issues and merge requests, emphasizing secrecy and reset procedures, and explaining the IP-restriction exception. Defenders should immediately search repositories, documentation, tickets, logs, and public pages for glimt addresses and older or customized incoming-mail token formats. Suspected exposure necessitates resetting the incoming email token under personal access-token settings, which invalidates associated project addresses.

Organizations should also review affected users' permissions, protected-branch rules, pipelines, variables, commits, and audit events, while treating every project email address as an account credential, not a harmless contact address. Cut SOC alert investigations by 21 minutes.