vulnerability Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git A researcher, depthfirst, has published a proof-of-concept exploit targeting GitLab 18.11.3 and earlier, allowing authenticated users to execute arbitrary commands as the ‘git’ user. The vulnerability stems from flaws within the Oj JSON parser and can be triggered by submitting specially crafted Jupyter notebooks. Whil… The Hacker News · Jul 25, 2026 High rcejupyterjson