Zereight Mcp-Gitlab vulnerabilities
4 known vulnerabilities affecting zereight/mcp-gitlab.
Total CVEs
4
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH1
Vulnerabilities
Page 1 of 1
CVE-2026-61560P2CRITICALPoC≥ 0, < 2.1.272026-09-16
CVE-2026-61560 [CRITICAL] CWE-22 @zereight/mcp-gitlab: Unauthenticated arbitrary file read via `upload_markdown` enables PAT exfiltration and full account takeover
@zereight/mcp-gitlab: Unauthenticated arbitrary file read via `upload_markdown` enables PAT exfiltration and full account takeover
### Summary
The SSE transport mode (`SSE=true`) exposes all MCP tools without any authentication. The `upload_markdown` tool reads arbitrary files from the server's local filesystem via an unsanitized `f
ghsa
CVE-2026-61462P3HIGHCVSS 8.6fixed in 2.1.182026-07-13
CVE-2026-61462 [HIGH] CWE-73 CVE-2026-61462: mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that al
mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints. Attackers can supply crafted job_id values like ../../../user to escape the intended path prefix and access arbitrary GitLab API resources using the operator's personal access token.
nvd
CVE-2026-61559P2CRITICAL≥ 0.0.1, < 2.1.272026-09-15
CVE-2026-61559 [CRITICAL] CWE-918 @zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery
@zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery
# Server-Side Request Forgery via X-GitLab-API-URL Header Allows Credential Theft
## Affected
- **Repository:** `zereight/gitlab-mcp`
- **Affected versions:** All versions through commit `74a8c83`
- **Patched versions:** None at time of report
## Severity
High. CVSS v3.1 8.5 (`AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N`)
## Description
Wh
ghsa
CVE-2026-61568P3CRITICAL≥ 0, < 2.1.302026-09-15
CVE-2026-61568 [CRITICAL] CWE-350 @zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport
@zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport
`@zereight/mcp-gitlab` exposes its Streamable HTTP MCP endpoint without an effective Host or Origin allowlist. A malicious web page can use DNS rebinding to route browser requests to a victim's local MCP listener while preserving an attacker-controlled `Host` and `Origin`. The server accepts those header
ghsa