Skip to content

project

GitLab

GitLab is a web-based DevOps platform offering Git repository hosting, CI/CD pipelines, issue tracking, and AI-assisted code review (Duo) for software teams.

Known aliases

  • GitLab CE
  • gitlab.com
  • GitLab Community Edition
  • GitLab EE
  • GitLab Enterprise Edition
  • GitLab Inc.
  • GTLB

Relationships

No evidence-backed relationships are recorded.

Current stories

security4 publishers

GitLab patches sandbox escape that lets Duo agent users run commands on self-hosted AI Gateways

GitLab patched CVE-2026-90970, a sandbox escape that lets any authenticated Duo Agent Platform user run arbitrary commands on a self-hosted AI Gateway. Customers on GitLab's hosted gateway are already protected, so the upgrade falls to Self-Managed shops that run their own.

Perspective Coverage

4 publishers
Builder
Builder 24%
Operator
Operator 59%
Investor
Investor 17%

Reality

Evidence78
Adoption
Insufficient
Hype gap+15
Incentives
Insufficient
Confidence74
build1 publisher

Cache lookahead brings a kaniko fork within 1.6x of BuildKit on GitLab runners

Kaniko's community fork, with cross-stage cache lookahead, ran 1.6x slower than BuildKit on GitLab.com runners in a dev.to benchmark. The 15x gap still quoted against kaniko dates from 2018, so teams choosing an in-cluster builder need figures from their own Dockerfiles.

Publishers:dev.to

Reality

Evidence40
Adoption
Insufficient
Hype gap+30
Incentives
Insufficient
Confidence35
build1 publisher

GitLab gives Duo Enterprise seat holders the single-pass AI reviewer by default

GitLab's v19.5 docs send AI reviews started by Duo Enterprise seat holders to the single-pass reviewer that reads only the merge request and its diffs. To check cross-file rules on every review, a group Owner has to move seat holders onto the credit-billed Code Review Flow.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap+5
Incentives
Insufficient
Confidence40
security3 publishers

Public READMEs are leaking GitLab email tokens that let any sender act as the account owner

Aikido found a dozen live GitLab 'email work item' addresses in public docs, each carrying a long-lived token that lets any mailbox act as its owner. GitLab calls it intended behavior, so maintainers must pull the address and reset the token.

Perspective Coverage

3 publishers
Builder
Builder 43%
Operator
Operator 52%
Investor
Investor 5%

Reality

Evidence68
Adoption28
Hype gap+10
Incentives52
Confidence60
security7 publishers

GitLab's 9.4 GraphQL bug went from patch to in-the-wild traffic in about two days

WatchTowr reproduced CVE-2026-19478 from the advisory and patch alone, then caught the first exploitation attempts on its honeypots. Self-managed owners do not get a week to schedule this.

Perspective Coverage

7 publishers
Builder
Builder 29%
Operator
Operator 62%
Investor
Investor 9%

Reality

Evidence72
Adoption
Insufficient
Hype gap+20
Incentives65
Confidence70
build3 publishers

A file.path parameter in GitLab's commit API reads server files before authentication

The fix ships in 19.3.2, 19.2.6 and 19.1.8, and scanning for the flaw started the day after disclosure. Whether you can tell if a read succeeded on your instance depends on whether your proxy logs request bodies.

Publishers:dev.todocs.gitlab.comwatchtowr.com

Perspective Coverage

3 publishers
Builder
Builder 22%
Operator
Operator 73%
Investor
Investor 5%

Reality

Evidence80
Adoption
Insufficient
Hype gap+15
Incentives45
Confidence74
security13 publishers

CISA sets a September 13 deadline for the MikroTrick RouterOS chain

Federal agencies now have three separate patch deadlines inside twelve days. The lowest-scoring pair of the five flaws added to KEV is the one with a documented 24-day intrusion campaign behind it.

Perspective Coverage

13 publishers
Builder
Builder 21%
Operator
Operator 76%
Investor
Investor 3%

Reality

Evidence68
Adoption
Insufficient
Hype gap+15
Incentives50
Confidence66
security3 publishers

BambooToken moves its Windows and Linux command channel onto MQTT brokers

Black Lotus Labs counted about a dozen compromised enterprises, mostly in Asia and South America, on a framework that has been publishing operator commands to infected hosts through IoT message brokers since 2024.

Perspective Coverage

3 publishers
Builder
Builder 27%
Operator
Operator 62%
Investor
Investor 11%

Reality

Evidence66
Adoption18
Hype gap+20
Incentives
Insufficient
Confidence64
build1 publisher

Trusting the repository author in VS Code runs the fake recruiter's task file

Microsoft's Defender Experts date the Contagious Interview campaign to December 2022. Its payload lands at the one hiring stage where a candidate is expected to clone and run a stranger's code. The same team tells employers to give staff a non-persistent VM for coding tests.

Publishers:dev.to

Reality

Evidence64
Adoption35
Hype gap+8
Incentives58
Confidence62

Earlier coverage

  1. The SaaSpocalypse thesis still has to get past the customer's pen-testers

    Leadership · September 16, 2026 · 1 publisher

  2. SaaStr's counterfactual Slack works out to 6 to 8 times a triangulated revenue base

    Invest · September 15, 2026 · 1 publisher

  3. Claude's Salesforce beta proposes changes like close-date updates for sellers to approve

    Build · September 15, 2026 · 1 publisher

  4. Origin inherits GitHub's read list for every repo a developer syncs into Cursor

    Build · September 14, 2026 · 1 publisher

  5. Check Point ships this week's VPN fix as a live patch for three versions and an upgrade for the rest

    Build · September 14, 2026 · 1 publisher

  6. East River rewrites the storage under Git without asking anyone to migrate

    Build · September 11, 2026 · 1 publisher

  7. OpenAI opened its first incident 57 days after agents found write access on Artifactory

    Build · September 10, 2026 · 2 publishers

  8. Testing teams adopted AI for writing tests 3.5 times as often as for judging risk

    Product · September 9, 2026 · 1 publisher

  9. Adding Git replicas made Datadog's CI fetches slower because every write went to all of them

    Build · September 6, 2026 · 1 publisher

  10. Opting into native Git in SageMaker Unified Studio turns every save into a staging decision

    Build · September 1, 2026 · 1 publisher

  11. An approving LLM comment sent an unguarded array index into a payment reconciliation job

    Build · August 29, 2026 · 1 publisher

  12. Oligo dates the crew behind ShadowRay 2.0's self-propagating botnet back to 2020

    Security · August 28, 2026 · 1 publisher

  13. Harness gives the coding agent its own permissions and its own audit trail

    Product · August 27, 2026 · 1 publisher

  14. Gogs checks the path, then follows the symlink out of the repository

    Build · August 27, 2026 · 1 publisher

  15. A repo compromise found in week four outlives GitHub's seven-day Git event log

    Security · August 27, 2026 · 1 publisher

  16. GitLab ships five security fixes and keeps the details sealed until October

    Build · August 23, 2026 · 1 publisher

  17. Partition, not consolidation: what a 43-minute Jenkins queue actually cost

    Build · August 21, 2026 · 1 publisher

  18. 678,000 French filers and one 9.4: the week's patch-and-notify work, with numbers attached

    Security · August 21, 2026 · 1 publisher

  19. The stability step is a branch, not a pipeline: inside one team's release-candidate discipline

    Build · August 21, 2026 · 1 publisher

  20. GitLab 19.3 puts agent runtime, inference models and secrets under one permission model

    Security · August 21, 2026 · 1 publisher

  21. Two hardware tokens, one wrong guess: why SSH keeps asking for your PIN twice

    Build · August 20, 2026 · 1 publisher

  22. GitLab bundles a zero-click GraphQL flaw with a CSRF bug, and only one needs a victim

    Build · August 18, 2026 · 1 publisher

  23. Optus's RHEL factory treats image sprawl as a pipeline defect, not an engineer's lapse

    Product · August 17, 2026 · 1 publisher

  24. Thirty MCP tools become three: the reliability bug is in your schema, not the model

    Build · August 15, 2026 · 1 publisher