CVE-2026-61559 PUBLISHED

@zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery

Assigner: GitHub_M
Reserved: 10.07.2026 Published: 15.09.2026 Updated: 15.09.2026

@zereight/mcp-gitlab is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1.27, when the environment variable ENABLE_DYNAMIC_API_URL=true is set, the server reads the X-GitLab-API-URL HTTP request header and uses it as the base URL for all outbound GitLab API calls made within that request. The server validates that the value is a well-formed URL (new URL(dynamicApiUrl)) but applies no allowlist or hostname restriction. The server then attaches the victim's Private-Token to every outbound fetch that uses the redirected URL. Any caller who can reach the HTTP transport can set X-GitLab-API-URL to an attacker-controlled host. The next GitLab API call the server makes delivers the victim's token to that host. Version 2.1.27 contains a patch.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
CVSS Score: 9.6

Product Status

Vendor zereight
Product gitlab-mcp
Versions
  • Version >= 0.0.1, < 2.1.27 is affected

References

Problem Types

  • CWE-918: Server-Side Request Forgery (SSRF) CWE