THREAT OPS › Threat News › [GHSA] GHSA-vmp7-252j-cwp7 (critical) — @zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport
[GHSA] GHSA-vmp7-252j-cwp7 (critical) — @zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport
GHSA-vmp7-252j-cwp7 Severity: critical CVE: CVE-2026-61568
@zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport
`@zereight/mcp-gitlab` exposes its Streamable HTTP MCP endpoint without an effective Host or Origin allowlist. A malicious web page can use DNS rebinding to route browser requests to a victim's local MCP listener while preserving an attacker-controlled `Host`
Indicators of compromise
- 74a8c834424ff557ad8bc6f225e4dc5acf80aa13sha1
- CVE-2026-61568cve
- http://127.0.0.1:18082/api/v4url
- http://127.0.0.1:8082/mcpurl
- http://127.0.0.1:${PORT}`url
Original source: https://github.com/advisories/GHSA-vmp7-252j-cwp7