@zereight/mcp-gitlab vulnerabilities
CVEs whose affected-version data names the @zereight/mcp-gitlab package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-61560Critical· 9.8PoC`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab
`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the SSE transport mode (`SSE=true`) exposes all MCP tools without any authentication. The `upload_markdown` tool reads arbitrary files from th…
GHSA-5648-rgj9-v224High· 8.1@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS
@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS
CVE-2026-61568Critical· 9.6`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab
`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expose the Streamable HTTP MCP endpoint without an effective Host or Origin allowlist. A malicious web page can use DNS rebinding to route bro…