🕵️ RESEARCH & DEEP DIVES
-
Researcher Publishes RCE PoC for GitLab 18.11.3 Allowing Authenticated Command Execution — The Hacker News
A researcher published a proof-of-concept for remote code execution on GitLab 18.11.3.- Applies to self-managed GitLab CE and EE versions 15.2.0 to 18.10.7, 18.11.0 to 18.11.4, and 19.0.0 to 19.0.1
- Vulnerability exploits Oj JSON parser bugs in GitLab's notebook renderer to execute commands as git user
- Triggered by an authenticated user committing two crafted Jupyter notebooks and requesting their diff
- No admin rights, CI runner access, victim interaction, or other project access required
- Exploitation leaks heap address to bypass ASLR and corrupts parser state to run system commands
-
Rockwell patches four high-severity code execution flaws in Arena Simulation software — SecurityWeek
Rockwell Automation patched four critical code execution vulnerabilities in Arena Simulation software.- Applies to Rockwell Automation's Arena Simulation software versions up to 17.00.00
- Four high-severity memory corruption flaws allow out-of-bounds write leading to arbitrary code execution
- Exploitation requires user interaction by opening a malicious Arena experiment or model file
- Code execution runs with the same privileges as the Arena process; pivoting depends on network segmentation
- No evidence of in-the-wild exploitation; vulnerabilities disclosed as CVE-2026-8085, CVE-2026-8312, CVE-2026-8313, CVE-2026-8314