Exposed GitLab Project Email Addresses Let Attackers Push Code
Private GitLab email addresses used for tasks and bug reports are being deliberately exposed, allowing unauthorized code pushes.

Private GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in README files, contributing guides, and bug report pages. These addresses are meant to streamline workflow but are now becoming a security vector.
According to BleepingComputer, malicious actors are exploiting this exposure to push unauthorized code into repositories, threatening the integrity of software projects and exposing them to potential supply chain attacks.
Security experts advise repository owners to immediately audit their documentation and public pages to remove any sensitive email addresses that could be leveraged by attackers for malicious code injection.
For development teams and tech communities, this incident highlights the critical need for proper credential management and continuous security checks across all public-facing project documentation.



