Web Hack List

Collected research

GitLab RCE via GitHub import

Shows how attacker-controlled GitHub import data becomes Sawyer objects whose to_s and bytesize methods can be overridden. Redis command construction then emits inconsistent protocol framing, allowing arbitrary Redis commands and the injection of jobs that lead to remote code execution.

Record

Published by
GitLab

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of GitLab, first published at the original source. Preserved copies are kept so the citation survives its host.