CRITICAL9.6npm
GHSA-2h44-8472-frjj· CVE-2026-61559@zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery
Modified: 9/15/2026
package
pkg:npm/%40zereight/mcp-gitlab
@zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery
Modified: 9/15/2026
@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS
Modified: 9/15/2026
@zereight/mcp-gitlab: Unauthenticated arbitrary file read via `upload_markdown` enables PAT exfiltration and full account takeover
Modified: 9/16/2026
@zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport
Modified: 9/15/2026