CVE-2026-61462
published 2026-07-13CVE-2026-61462: mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary…
PriorityP357high8.6CVSS 3.1
AVNACLPRNUINSCCHINAN
EPSS
0.51%
41.1th percentile
mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints. Attackers can supply crafted job_id values like ../../../user to escape the intended path prefix and access arbitrary GitLab API resources using the operator's personal access token.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zereight | mcp-gitlab | < 2.1.18 | 2.1.18 |
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
nvdv4.09.2CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
zereight mcp-gitlab up to 2.1.17 Build build/index.js job_id path traversal
vuldb·2026-07-13·CVSS 8.6
CVE-2026-61462 [HIGH] zereight mcp-gitlab up to 2.1.17 Build build/index.js job_id path traversal
A vulnerability categorized as problematic has been discovered in zereight mcp-gitlab up to 2.1.17. This impacts an unknown function of the file build/index.js of the component Build. Such manipulation of the argument job_id leads to path traversal.
This vulnerability is traded as CVE-2026-61462. The attack may be launched remotely. There is no exploit available.
GHSA
mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints.
ghsa_unreviewed·2026-07-13
CVE-2026-61462 [CRITICAL] CWE-73 mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints.
mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints. Attackers can supply crafted job_id values like ../../../user to escape the intended path prefix and access arbitrary GitLab API resources using the operator's personal access token.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/zereight/gitlab-mcphttps://github.com/zereight/gitlab-mcp/commit/e2a81a047ab8750fa5bfa1763b5d85e5616f3994https://github.com/zereight/gitlab-mcp/issues/587https://www.vulncheck.com/advisories/mcp-gitlab-path-traversal-via-job-id-parameterhttps://github.com/zereight/gitlab-mcp/issues/587
2026-07-13
Published