THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-2h44-8472-frjj (critical) — @zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery

[GHSA] GHSA-2h44-8472-frjj (critical) — @zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery

highgithub_advisoriesPublished 2026-09-15

GHSA-2h44-8472-frjj Severity: critical CVE: CVE-2026-61559

@zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery

# Server-Side Request Forgery via X-GitLab-API-URL Header Allows Credential Theft

## Affected

- **Repository:** `zereight/gitlab-mcp` - **Affected versions:** All versions through commit `74a8c83` - **Patched versions:** None at time of report

## Severity

High. CVSS v3.1

Indicators of compromise

Original source: https://github.com/advisories/GHSA-2h44-8472-frjj