The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

In September 2026, Aikido Security researchers discovered that GitLab's incoming email addresses contain non-expiring access tokens that grant broad privileges across an organization's public and private projects. These automatically assigned email addresses, designed for creating issues via email, can be weaponized by attackers who obtain them to push malicious code, bypass IP restrictions, and execute CI/CD jobs without direct account access. The vulnerability affects the entire GitLab ecosystem, with researchers finding exposed addresses for popular open-source projects during a brief internet scan.

This incident highlights the growing sophistication of supply chain attacks targeting developer platforms and the hidden security implications of seemingly benign productivity features. As organizations increasingly rely on DevOps platforms for critical infrastructure, attackers are exploiting overlooked authentication mechanisms to compromise software supply chains at scale.

Why This Matters Now

Supply chain attacks via developer platforms are surging in 2026, with threat actors exploiting hidden authentication tokens in productivity features to bypass traditional security controls and inject malicious code directly into software repositories.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

GitLab email addresses contain non-expiring tokens that grant broad access to an organization's projects, allowing attackers to push malicious code, create merge requests, and execute CI/CD jobs without account access.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely have constrained the GitLab token exploitation by segmenting repository access and limiting lateral movement across projects. The fabric's identity-aware controls could have reduced the blast radius from exposed email tokens.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Identity-aware access controls would likely have constrained the scope of repository access even when tokens were exposed, limiting which projects could be reached through compromised email addresses.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Microsegmentation policies would likely have prevented path manipulation attacks by enforcing strict project-to-project access boundaries, constraining privilege escalation across repository namespaces even with valid tokens.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic controls would likely have blocked cross-project enumeration attempts, constraining lateral access patterns between GitLab repositories and reducing the attack surface for project ID guessing.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Centralized visibility controls would likely have detected anomalous merge request patterns and CI/CD trigger behaviors, constraining persistent access through automated pipeline manipulation and covert channels.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress policy enforcement would likely have constrained bulk data extraction through merge requests, limiting the volume and frequency of repository content that could be exfiltrated via email-based mechanisms.

Impact (Mitigations)

While segmentation would likely limit supply chain compromise to specific project boundaries, any successful code injection could still affect downstream applications consuming those particular repositories within the constrained scope.

Impact at a Glance

Affected Business Functions

  • Software Development
  • DevOps CI/CD Pipeline
  • Source Code Management
  • Project Management
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Potential exposure of private source code repositories, proprietary software projects, intellectual property, and development secrets through unauthorized access to GitLab projects via compromised incoming email tokens

Recommended Actions

  • • Implement Zero Trust Segmentation to enforce least privilege access and prevent unauthorized cross-project token reuse through identity-based policy controls
  • • Deploy Egress Security & Policy Enforcement to monitor and control outbound communications from development environments, blocking unauthorized data exfiltration attempts
  • • Establish Multicloud Visibility & Control to detect anomalous interactions and suspicious automation patterns across GitLab and integrated development platforms
  • • Enable Threat Detection & Anomaly Response capabilities to baseline normal development workflows and alert on covert email-based access patterns
  • • Rotate all GitLab incoming email tokens organization-wide and scan repositories for exposed addresses as part of comprehensive secrets management practices

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image