
Software
a single request, no login, no clicks — and your public GitLab repo is gone
GitLab's emergency patch fixes a code-injection bug that let an unauthenticated attacker delete repositories, forge merge records, or ban maintainers in one HTTP request — and researchers reproduced it within minutes of the advisory going live.
Priya Nair · 12h ago · 6 min