The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

In September 2026, security researchers at Aikido discovered that private GitLab email addresses containing long-lived authentication tokens were being deliberately exposed in public documentation by project maintainers. These addresses, part of GitLab's "Email work item to this project" feature, allow attackers to push code to protected branches, access private repositories, steal CI/CD secrets, and compromise developer accounts without proper authentication validation. The vulnerability affects popular open-source projects, creating significant supply chain risks as attackers can modify email suffixes to escalate from creating issues to opening merge requests.

This incident highlights the growing trend of misunderstood security features in DevOps platforms leading to supply chain compromises, as organizations increasingly rely on automated development workflows without fully comprehending the associated security implications.

Why This Matters Now

Supply chain attacks targeting developer platforms have increased 650% in 2026, with attackers specifically exploiting misconfigurations in CI/CD pipelines and version control systems to inject malicious code into trusted software repositories.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Organizations should audit public documentation for exposed GitLab email addresses, reset tokens for previously exposed projects, and implement proper access controls for CI/CD workflows.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have constrained this GitLab token abuse incident by limiting exposed service access points and reducing lateral movement across repository boundaries. Zero Trust segmentation would likely have contained the blast radius from token misuse to specific project scopes.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Service exposure policies would likely have restricted access to GitLab email endpoints and could have limited the reachability of token-based authentication mechanisms from external sources.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Identity-aware access controls would likely have limited privilege scope by restricting token capabilities to specific functions and could have reduced the ability to escalate permissions through email manipulation.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Microsegmentation policies would likely have constrained cross-repository access and could have limited the scope of CI/CD pipeline traversal across different project boundaries within the GitLab environment.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: API traffic monitoring and control policies would likely have detected anomalous email-based GitLab interactions and could have constrained persistent access patterns through behavioral analysis.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Data loss prevention policies would likely have constrained bulk repository access and could have limited the scope of CI/CD secret extraction through controlled egress monitoring.

Impact (Mitigations)

While malicious code injection would likely still pose supply chain risks to downstream consumers, the scope of affected repositories and compromised secrets would be significantly reduced through earlier containment.

Impact at a Glance

Affected Business Functions

  • Software Development and Version Control
  • Source Code Management
  • CI/CD Pipeline Operations
  • Open Source Project Maintenance
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Private source code repositories, CI/CD secrets and variables, confidential project issues, and merge request capabilities. Attackers could potentially access proprietary code, steal intellectual property, inject malicious code into protected branches, and compromise software supply chains of affected open source projects.

Recommended Actions

  • • Implement Zero Trust Segmentation to enforce least privilege access controls and prevent token-based lateral movement across GitLab projects and repositories
  • • Deploy Egress Security & Policy Enforcement to monitor and control outbound data flows from development environments and detect unauthorized repository access patterns
  • • Enable Multicloud Visibility & Control to gain centralized observability into GitLab API interactions and identify anomalous automation patterns across development workflows
  • • Establish Threat Detection & Anomaly Response capabilities to baseline normal GitLab usage patterns and alert on suspicious email-based API interactions or unusual merge request activities
  • • Apply Cloud Native Security Fabric (CNSF) controls to provide real-time inspection and policy enforcement for development tool integrations and supply chain security risks

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image