“The biggest challenge with the existing design is anyone with an email account can email to that address and act as that GitLab user,” Joseph Leon, security researcher at Aikido told CSO. “If GitLab required the ‘from’ address of the account sending the email to match the GitLab user’s email address, most of the risk would be mitigated.”
IP restrictions ignored
GitLab does allow users to set restrictions on which IP addresses may access their account — but those restrictions do not apply to emails. “GitLab blocked our browser and rejected git clone. It accepted the email, and the commit landed on main,” Aikido said.
The behavior is intended, and not a vulnerability, according to GitLab. Aikido questions that assessment, arguing that “GitLab built a credential that reaches every project in the account and bypasses IP restrictions, then presented it as an email address.”



