We successfully achieved an RCE on GitLab in its default configuration.
Historically, most GitLab RCEs have lived in the web or application-logic layers. This time, guided by the @depthfirstlabs spirit, we went deeper: into the low-level gem dependency chain beneath GitLab.
The result? By sending crafted JSON data, we could exploit memory-corruption vulnerabilities buried deep in that chain and take control of the GitLab application server.
@depthfirstlabs brings together some of the smartest people, and is building the best security AI agent. Follow our work, and come join us!
Read more about this in the comment...