Zereight Gitlab-Mcp vulnerabilities
3 known vulnerabilities affecting zereight/gitlab-mcp.
Total CVEs
3
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL3
Vulnerabilities
Page 1 of 1
CVE-2026-61560P2CRITICALCVSS 9.8PoCfixed in 2.1.272026-09-15
CVE-2026-61560 [CRITICAL] CWE-22 CVE-2026-61560: `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the S
`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the SSE transport mode (`SSE=true`) exposes all MCP tools without any authentication. The `upload_markdown` tool reads arbitrary files from the server's local filesystem via an unsanitized `file_path` parameter and uploads them to a GitLab project. Combin
nvd
CVE-2026-61559P2CRITICALCVSS 9.6v>= 0.0.1, < 2.1.272026-09-15
CVE-2026-61559 [CRITICAL] CWE-918 CVE-2026-61559: `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and
`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1.27, when the environment variable `ENABLE_DYNAMIC_API_URL=true` is set, the server reads the `X-GitLab-API-URL` HTTP request header and uses it as the base URL for all outbound GitLab API calls made within that request. The serve
nvd
CVE-2026-61568P3CRITICALCVSS 9.6fixed in 2.1.302026-09-15
CVE-2026-61568 [CRITICAL] CWE-350 CVE-2026-61568: `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expos
`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expose the Streamable HTTP MCP endpoint without an effective Host or Origin allowlist. A malicious web page can use DNS rebinding to route browser requests to a victim's local MCP listener while preserving an attacker-controlled `Host` and `Origin`. The
nvd