Back to advisories

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

A public PoC exploit now exists for a critical RCE vulnerability affecting self-managed GitLab instances. Any authenticated user can execute arbitrary commands as the 'git' system user by uploading malicious Jupyter notebooks and requesting diffs. Many instances remain vulnerable because the underlying Oj gem patch from six weeks ago was not flagged as a security update.

CRITICALAdvisoryJul 27, 2026
Action required
Immediately verify all self-managed GitLab instances are running the latest patched version of the Oj gem. Check git server logs and audit trails for suspicious Jupyter notebook commits and diff requests from authenticated users. If unpatched, restrict Jupyter notebook diff functionality or isolate instances until patching is complete.
Affected products
GitLabOjdepthfirst