{"id":"CVE-2026-61559","title":"`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab","summary":"`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1.27, when the environment variable `ENABLE_DYNAMIC_API_URL=true` is set, the server reads the `X-GitLab-API-URL` HTTP…","severity":"critical","cvss":9.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","cwe":["CWE-918"],"vendor":"zereight","product":"gitlab-mcp","affected":["gitlab-mcp >= 0.0.1, < 2.1.27"],"patched":["@zereight/mcp-gitlab 2.1.27"],"published":"2026-09-15","updated":"2026-09-17","sourceUpdated":"2026-09-17T17:16:44.757","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-61559","references":[{"url":"https://github.com/zereight/gitlab-mcp/commit/6ffb4cc70706fd05b1ab80901676bc2998b6db6d","label":"security-advisories@github.com"},{"url":"https://github.com/zereight/gitlab-mcp/pull/625","label":"security-advisories@github.com"},{"url":"https://github.com/zereight/gitlab-mcp/releases/tag/v2.1.27","label":"security-advisories@github.com"},{"url":"https://github.com/zereight/gitlab-mcp/security/advisories/GHSA-2h44-8472-frjj","label":"security-advisories@github.com"},{"url":"https://github.com/zereight/gitlab-mcp/security/advisories/GHSA-2h44-8472-frjj","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://github.com/advisories/GHSA-2h44-8472-frjj"}],"tags":["nvd","cve.org","exploit-available","ghsa","npm"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"total","timestamp":"2026-09-17T16:49:44.156114Z"},"epss":0.00271,"epssPercentile":0.19506,"aliases":["GHSA-2h44-8472-frjj"],"ecosystem":"npm","ingestedAt":"2026-09-15T21:44:50.635Z","slug":"CVE-2026-61559","body":"## Overview\n\n`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1.27, when the environment variable `ENABLE_DYNAMIC_API_URL=true` is set, the server reads the `X-GitLab-API-URL` HTTP request header and uses it as the base URL for all outbound GitLab API calls made within that request. The server validates that the value is a well-formed URL (`new URL(dynamicApiUrl)`) but applies no allowlist or hostname restriction. The server then attaches the victim's `Private-Token` to every outbound fetch that uses the redirected URL. Any caller who can reach the HTTP transport can set `X-GitLab-API-URL` to an attacker-controlled host. The next GitLab API call the server makes delivers the victim's token to that host. Version 2.1.27 contains a patch.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-61559)\n\nAffected packages:\n\n- `@zereight/mcp-gitlab >= 0.0.1, < 2.1.27`\n\nPatched in:\n\n- `@zereight/mcp-gitlab 2.1.27`\n\nSource: https://github.com/advisories/GHSA-2h44-8472-frjj","depth":"abyssal","depthScore":65,"depthScoreParts":{"impact":52.8,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":206467,"id":"CVE-2026-61559","ts":1789665848999,"field":"exploit_available","old":"false","new":"true"}]}