PT-2026-93172 · Npm · @Zereight/Mcp-Gitlab
CVE-2026-61560
·
Published
2026-09-15
·
Updated
2026-09-28
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
@zereight/mcp-gitlab versions prior to 2.1.27
Description
When the SSE transport mode is enabled via
SSE=true, all Model Context Protocol (MCP) tools are exposed without authentication. This is the default configuration for Docker deployments. An unauthenticated network-reachable attacker can exploit the /sse and /messages endpoints to invoke tools using the server's configured Personal Access Token (PAT). Specifically, the upload markdown() function allows for arbitrary file reads from the server's local filesystem because the file path parameter is not sanitized. By reading /proc/self/environ, an attacker can steal the GITLAB PERSONAL ACCESS TOKEN and achieve full takeover of the associated GitLab account, including access to repositories, CI/CD secrets, and admin functions if applicable.Recommendations
Update @zereight/mcp-gitlab to version 2.1.27.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Zereight/Mcp-Gitlab