VDB
Sign up

package

npm/@zereight/mcp-gitlab

pkg:npm/%40zereight/mcp-gitlab

HIGH8.1npm
GHSA-5648-rgj9-v224

@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS

Modified: 9/15/2026

CRITICAL9.8npm
GHSA-cv3r-c5h8-f4g5· CVE-2026-61560

@zereight/mcp-gitlab: Unauthenticated arbitrary file read via `upload_markdown` enables PAT exfiltration and full account takeover

Modified: 9/16/2026