Back to news

GitLab RCE Exploit Published; LG Cracks Down on Smart TV Proxy Apps

A low-privilege GitLab attack chain is now public, while LG moves to purge residential proxy software from its smart TV platform.

GitLab RCE Exploit Published; LG Cracks Down on Smart TV Proxy Apps

What happened

Security researcher Yuhang Wu released a working exploit targeting self-managed GitLab instances running version 18.11.3 and earlier. Any authenticated user — no admin credentials, no CI runner access, and no victim interaction required — can trigger remote code execution by submitting two specially crafted Jupyter notebooks and requesting a diff between them. The commands execute under the git system user, giving an attacker meaningful footholds into repository infrastructure. Separately, LG Electronics USA announced it will suspend webOS apps found to be enrolling smart televisions as residential proxy nodes, after researchers reported that more than 42 percent of apps in its storefront were quietly routing third-party internet traffic through users' home devices.

Why it matters for your business

The GitLab vulnerability is particularly dangerous for organizations running self-hosted instances, which are common in regulated industries and enterprises that keep source code off cloud-managed platforms. Because the attack requires only a valid account, any insider or compromised contractor credential becomes a potential launchpad for code theft, supply chain tampering, or lateral movement. Teams should audit their GitLab version immediately and apply vendor patches before threat actors operationalize this publicly available PoC. On the smart TV front, the LG findings underscore that consumer-grade devices on corporate or home-office networks can silently participate in proxy botnets, making them vectors for data exfiltration or fraud — a risk that network segmentation policies should explicitly address.

What to watch next

GitLab is expected to issue a formal security advisory and patched release; administrators should monitor the official security release page and treat any delay as an elevated-risk window. For the LG story, regulators and app store operators in other hardware ecosystems — smart speakers, streaming sticks, connected appliances — may face pressure to audit their own catalogues for similar proxy-as-a-service schemes.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp