Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 6.2 Node.js & npm GHSA-cv3r-c5h8-f4g5 CVE-2026-61560 GHSA-vmp7-252j-cwp7 CVE-2026-61568

Four Critical Flaws in @zereight/mcp-gitlab Allow Unauthenticated GitLab Account Takeover

The npm package @zereight/mcp-gitlab, a Model Context Protocol server for GitLab, has four separate advisories covering unauthenticated remote file read, SSRF, DNS rebinding, and multiple safety-control bypasses. Several issues allow unauthenticated attackers to steal GitLab access tokens. Fixes are available in versions 2.1.27 and 2.1.30.

AI summary

Security researchers have published four separate advisories against `@zereight/mcp-gitlab`, an npm package that implements a Model Context Protocol (MCP) server for GitLab. The issues range from unauthenticated arbitrary file read that can lead to full GitLab account takeover, to server-side request forgery, DNS rebinding against the local MCP transport, and a set of safety-control bypasses affecting read-only mode and project allow-lists. Several of these conditions exist in default configurations, including the default Docker deployment. Patches are available across versions 2.1.27 and 2.1.30, depending on the specific advisory.

What happened

Four distinct advisories were published for `@zereight/mcp-gitlab`: - **CVE-2026-61560** (CVSS 9.8): When SSE transport is enabled (`SSE=true`), all MCP tools are exposed without authentication. The `upload_markdown` tool can read arbitrary files from the server's local filesystem via an unsanitized `file_path` parameter and upload them to a GitLab project, allowing an unauthenticated network-reachable attacker to read `/proc/self/environ` and steal the server's GitLab Personal Access Token. This is the default configuration for Docker deployments. - **CVE-2026-61568** (CVSS 9.6): Versions prior to 2.1.30 expose the Streamable HTTP MCP endpoint without an effective Host or Origin allowlist, allowing a malicious web page to use DNS rebinding to route browser requests to a victim's local MCP listener while preserving attacker-controlled Host and Origin headers. - **CVE-2026-61559** (CVSS 9.6): When `ENABLE_DYNAMIC_API_URL=true` is set, the server reads the `X-GitLab-API-URL` request header and uses it as the base URL for outbound GitLab API calls, without any allowlist or hostname restriction. The server attaches the victim's Private-Token to requests sent to the attacker-controlled host. - **GHSA-5648-rgj9-v224** (CVSS 8.1): A set of safety-control bypasses, including a read-only mode bypass and project allow-list bypass in the `execute_graphql` tool, unauthenticated Streamable HTTP access under certain credential configurations, unauthenticated SSE access by default, an unauthenticated session-exhaustion denial-of-service condition, and a prompt-injection surface via verbatim CI job trace output.

Technical cause

The advisories describe several distinct root causes. For CVE-2026-61560, the SSE transport mode exposes MCP tools without authentication by default, and the `upload_markdown` tool does not sanitize the `file_path` parameter, permitting arbitrary local file reads that can be exfiltrated to a GitLab project. For CVE-2026-61568, the Streamable HTTP endpoint lacks an effective Host/Origin allowlist, making it vulnerable to DNS rebinding. For CVE-2026-61559, the server validates that the `X-GitLab-API-URL` header is a well-formed URL but applies no allowlist or hostname restriction, enabling SSRF with the victim's Private-Token attached to the redirected request. GHSA-5648-rgj9-v224 documents multiple independent defects: a regex-based write-detection bypass in `execute_graphql` that misclassifies certain GraphQL mutations as read-only, missing project-scope enforcement in the same tool, authentication gating logic that omits cookie-based and OAuth-based startup modes, SSE transport created without DNS-rebinding protections, and a token-validation routine that only checks length and character set rather than verifying the token upstream, enabling session-exhaustion attacks.

Why it matters

Several of these issues allow an unauthenticated, network-reachable attacker to obtain the server's GitLab Personal Access Token or Private-Token, which can lead to full GitLab account takeover with the privileges associated with that token. Because the server is designed to bridge an LLM agent to GitLab, the safety-control bypasses described in GHSA-5648-rgj9-v224 are particularly significant: they can defeat read-only mode and project allow-lists that operators may rely on as their primary safety boundary when granting an AI agent access to GitLab.

Who is affected

Anyone running `@zereight/mcp-gitlab` is potentially affected, depending on configuration. CVE-2026-61560 affects deployments using SSE transport mode, including the default Docker deployment configuration. CVE-2026-61568 affects deployments exposing the Streamable HTTP MCP endpoint. CVE-2026-61559 affects deployments with `ENABLE_DYNAMIC_API_URL=true` set. The issues in GHSA-5648-rgj9-v224 affect deployments relying on read-only mode or project allow-lists as safety controls, deployments using cookie-path or OAuth-based authentication for Streamable HTTP, and deployments using default SSE configuration.

Affected versions

`@zereight/mcp-gitlab`: - CVE-2026-61560: versions before 2.1.27 are affected; fixed in 2.1.27. - CVE-2026-61568: versions before 2.1.30 are affected; fixed in 2.1.30. - CVE-2026-61559: versions from 0.0.1 before 2.1.27 are affected; fixed in 2.1.27. - GHSA-5648-rgj9-v224: versions before 2.1.30 are affected; fixed in 2.1.30. The advisory notes that the reviewed commit corresponds to package version 2.1.28, which was found to still contain these defects.

Fixes and mitigation

Patches are available: version 2.1.27 addresses CVE-2026-61560 and CVE-2026-61559; version 2.1.30 addresses CVE-2026-61568 and the issues described in GHSA-5648-rgj9-v224. Operators should upgrade to version 2.1.30 to receive fixes for all four advisories, since it is the later of the two fixed versions and supersedes 2.1.27 for the issues it addresses. No specific interim workarounds beyond upgrading are described in the available facts.

Recommended action

Upgrade `@zereight/mcp-gitlab` to version 2.1.30 as soon as possible. Review deployment configuration for SSE transport, Streamable HTTP transport, and the `ENABLE_DYNAMIC_API_URL` setting, and confirm that authentication is enforced for all enabled transports after upgrading. If read-only mode or `GITLAB_ALLOWED_PROJECT_IDS` is used as a safety boundary for an AI agent, verify against the vendor's fix that these controls are enforced correctly following the update, since GHSA-5648-rgj9-v224 describes these controls as bypassable prior to the fix.

PatchBriefing score

6.2 / 10 · Medium

Official CVSS: 9.8

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Why this score

The patchwire scores for these advisories (ranging from 4.7 to 6.2) are driven primarily by high CVSS base scores (8.1 to 9.8), reflecting network-exploitable vulnerabilities requiring no or minimal privileges. Scores are moderated by the absence of confirmed known exploitation, public exploit code, or EPSS data for most advisories. CVE-2026-61560 and CVE-2026-61568 received additional contribution for being unauthenticated and remotely exploitable with no user interaction (CVE-2026-61560) or requiring only limited user interaction (CVE-2026-61568). These are deterministic scores based on the listed factors and have not been altered.

Affected versions

@zereight/mcp-gitlab < 2.1.27
vulnerable
≥ 2.1.27
patched
@zereight/mcp-gitlab < 2.1.30
vulnerable
≥ 2.1.30
patched
@zereight/mcp-gitlab >= 0.0.1, < 2.1.27
vulnerable
≥ 2.1.27
patched
@zereight/mcp-gitlab < 2.1.30
vulnerable
≥ 2.1.30
patched

Reported fixes

Patches are available: version 2.1.27 addresses CVE-2026-61560 and CVE-2026-61559; version 2.1.30 addresses CVE-2026-61568 and the issues described in GHSA-5648-rgj9-v224. Operators should upgrade to version 2.1.30 to receive fixes for all four advisories, since it is the later of the two fixed versions and supersedes 2.1.27 for the issues it addresses. No specific interim workarounds beyond upgrading are described in the available facts.

How this was built

7 source records were collected, matched and used to prepare the report above.

  • GitHub Advisory Database database
  • NVD (NIST) database
  • GitHub Advisory Database database
  • NVD (NIST) database
  • GitHub Advisory Database database
  • NVD (NIST) database
Unified report
Four Critical Flaws in @zereight/mcp-gitlab Allow Unauthenticated GitLab Account Takeover
1 article · 7 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email