THREAT OPS › Threat News › [GHSA] GHSA-2h44-8472-frjj (critical) — @zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery
[GHSA] GHSA-2h44-8472-frjj (critical) — @zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery
GHSA-2h44-8472-frjj Severity: critical CVE: CVE-2026-61559
@zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery
# Server-Side Request Forgery via X-GitLab-API-URL Header Allows Credential Theft
## Affected
- **Repository:** `zereight/gitlab-mcp` - **Affected versions:** All versions through commit `74a8c83` - **Patched versions:** None at time of report
## Severity
High. CVSS v3.1
Indicators of compromise
- CVE-2026-61559cve
- http://TARGET:3002/mcpurl
- http://ATTACKER:9099/api/v4url
Original source: https://github.com/advisories/GHSA-2h44-8472-frjj