zereight has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was September 2026 with 4. The median CVSS is 9.6 (critical), with 3 rated critical. Most affected products: @zereight/mcp-gitlab (3), gitlab-mcp (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 9.6
- Publish → KEV
- —
- Last 90 days
- 4 prev 0
Worst active — by depth score
CVE-2026-61560Critical· 9.8`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab66CVE-2026-61559Critical· 9.6`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab65CVE-2026-61568Critical· 9.6`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab53GHSA-5648-rgj9-v224High· 8.1@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS45
zereight vulnerabilities
CVEs affecting zereight, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-61560Critical· 9.8PoC`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab
`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the SSE transport mode (`SSE=true`) exposes all MCP tools without any authentication. The `upload_markdown` tool reads arbitrary files from th…
GHSA-5648-rgj9-v224High· 8.1@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS
@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS
CVE-2026-61568Critical· 9.6`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab
`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expose the Streamable HTTP MCP endpoint without an effective Host or Origin allowlist. A malicious web page can use DNS rebinding to route bro…
CVE-2026-61559Critical· 9.6PoC`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab
`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1.27, when the environment variable `ENABLE_DYNAMIC_API_URL=true` is set, the server reads the `X-GitLab-API-URL` HTTP…