---
id: CVE-2026-61559
title: '`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab'
summary: >-
  `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting
  in version 0.0.1 and prior to version 2.1.27, when the environment variable
  `ENABLE_DYNAMIC_API_URL=true` is set, the server reads the `X-GitLab-API-URL`
  HTTP…
severity: critical
cvss: 9.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'
cwe:
  - CWE-918
vendor: zereight
product: gitlab-mcp
affected:
  - 'gitlab-mcp >= 0.0.1, < 2.1.27'
patched:
  - '@zereight/mcp-gitlab 2.1.27'
published: '2026-09-15'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T17:16:44.757'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-61559'
references:
  - url: >-
      https://github.com/zereight/gitlab-mcp/commit/6ffb4cc70706fd05b1ab80901676bc2998b6db6d
    label: security-advisories@github.com
  - url: 'https://github.com/zereight/gitlab-mcp/pull/625'
    label: security-advisories@github.com
  - url: 'https://github.com/zereight/gitlab-mcp/releases/tag/v2.1.27'
    label: security-advisories@github.com
  - url: >-
      https://github.com/zereight/gitlab-mcp/security/advisories/GHSA-2h44-8472-frjj
    label: security-advisories@github.com
  - url: >-
      https://github.com/zereight/gitlab-mcp/security/advisories/GHSA-2h44-8472-frjj
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: 'https://github.com/advisories/GHSA-2h44-8472-frjj'
tags:
  - nvd
  - cve.org
  - exploit-available
  - ghsa
  - npm
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-17T16:49:44.156114Z'
epss: 0.00271
epssPercentile: 0.19549
aliases:
  - GHSA-2h44-8472-frjj
ecosystem: npm
ingestedAt: '2026-09-15T21:44:50.635Z'
---

## Overview

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1.27, when the environment variable `ENABLE_DYNAMIC_API_URL=true` is set, the server reads the `X-GitLab-API-URL` HTTP request header and uses it as the base URL for all outbound GitLab API calls made within that request. The server validates that the value is a well-formed URL (`new URL(dynamicApiUrl)`) but applies no allowlist or hostname restriction. The server then attaches the victim's `Private-Token` to every outbound fetch that uses the redirected URL. Any caller who can reach the HTTP transport can set `X-GitLab-API-URL` to an attacker-controlled host. The next GitLab API call the server makes delivers the victim's token to that host. Version 2.1.27 contains a patch.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-61559)

Affected packages:

- `@zereight/mcp-gitlab >= 0.0.1, < 2.1.27`

Patched in:

- `@zereight/mcp-gitlab 2.1.27`

Source: https://github.com/advisories/GHSA-2h44-8472-frjj
