PT-2026-93172 · Npm · @Zereight/Mcp-Gitlab

CVE-2026-61560

·

Published

2026-09-15

·

Updated

2026-09-28

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions @zereight/mcp-gitlab versions prior to 2.1.27
Description When the SSE transport mode is enabled via SSE=true, all Model Context Protocol (MCP) tools are exposed without authentication. This is the default configuration for Docker deployments. An unauthenticated network-reachable attacker can exploit the /sse and /messages endpoints to invoke tools using the server's configured Personal Access Token (PAT). Specifically, the upload markdown() function allows for arbitrary file reads from the server's local filesystem because the file path parameter is not sanitized. By reading /proc/self/environ, an attacker can steal the GITLAB PERSONAL ACCESS TOKEN and achieve full takeover of the associated GitLab account, including access to repositories, CI/CD secrets, and admin functions if applicable.
Recommendations Update @zereight/mcp-gitlab to version 2.1.27.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61560
GHSA-CV3R-C5H8-F4G5

Affected Products

@Zereight/Mcp-Gitlab