THREAT OPS › Threat News › [GHSA] GHSA-5648-rgj9-v224 (high) — @zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS
[GHSA] GHSA-5648-rgj9-v224 (high) — @zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS
GHSA-5648-rgj9-v224 Severity: high CVE: None
@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS
### Summary @zereight/mcp-gitlab exposes GitLab to an LLM agent while relying on read-only mode, a project allow-list, and transport auth as its safety controls. Five defects defeat those controls
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- 60adcc0de5b0e96c4c2029f7a25d2775946421d8sha1
- http://127.0.0.1:3002/mcpurl
Original source: https://github.com/advisories/GHSA-5648-rgj9-v224