CVE-2026-61559
published 2026-09-15CVE-2026-61559: `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1.27, when the environment variable…
PriorityP260critical9.6CVSS 3.1
AVNACLPRLUINSCCHIHAN
EPSS
0.43%
34.4th percentile
`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1.27, when the environment variable `ENABLE_DYNAMIC_API_URL=true` is set, the server reads the `X-GitLab-API-URL` HTTP request header and uses it as the base URL for all outbound GitLab API calls made within that request. The server validates that the value is a well-formed URL (`new URL(dynamicApiUrl)`) but applies no allowlist or hostname restriction. The server then attaches the victim's `Private-Token` to every outbound fetch that uses the redirected URL. Any caller who can reach the HTTP transport can set `X-GitLab-API-URL` to an attacker-controlled host. The next GitLab API call the server makes delivers the victim's token to that host. Version 2.1.27 contains a patch.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zereight | gitlab-mcp | — | — |
| zereight | mcp-gitlab | >= 0.0.1 < 2.1.27 | 2.1.27 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/zereight/gitlab-mcp/commit/6ffb4cc70706fd05b1ab80901676bc2998b6db6dhttps://github.com/zereight/gitlab-mcp/pull/625https://github.com/zereight/gitlab-mcp/releases/tag/v2.1.27https://github.com/zereight/gitlab-mcp/security/advisories/GHSA-2h44-8472-frjjhttps://github.com/zereight/gitlab-mcp/security/advisories/GHSA-2h44-8472-frjj
2026-09-15
Published