@zereight/mcp-gitlab
npm3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @zereight/mcp-gitlabpage 1 of 1
- CVE-2026-61559CRITICALCVSS 9.6EG 9.6✓ Fixed in 2.1.272026-09-15
`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1.27, when the environment variable `ENABLE_DYNAMIC_API_URL=true` is set, the server reads the `X-GitLab-API-URL` HTTP r…
- CVE-2026-61560CRITICALCVSS 9.8EG 9.8✓ Fixed in 2.1.272026-09-15
`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the SSE transport mode (`SSE=true`) exposes all MCP tools without any authentication. The `upload_markdown` tool reads arbitrary files from the …
- CVE-2026-61568CRITICALCVSS 9.6EG 9.6✓ Fixed in 2.1.302026-09-15
`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expose the Streamable HTTP MCP endpoint without an effective Host or Origin allowlist. A malicious web page can use DNS rebinding to route brows…
Check whether @zereight/mcp-gitlab is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @zereight/mcp-gitlab CVEs against the assets you own.
Start Free Scan →