A working proof-of-concept exploit for a remote code execution vulnerability in self-managed GitLab has been published, putting every unpatched instance on the internet at immediate risk.