← Back to feed
research PortSwigger Research

SAML roulette: the hacker always wins

PortSwigger Research GitLab

Introduction In this post, we’ll show precisely how to chain round-trip attacks and namespace confusion to achieve unauthenticated admin access on GitLab Ent...

Read the full story PortSwigger Research →

Related Coverage

research What's in a tag name? JavaScript, apparently PortSwigger Research · Aug 25 research State divergence enables unauthorized access Trail of Bits · Aug 25 research The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution Unit 42 · Aug 25