THREAT OPS › Threat News › [GHSA] GHSA-cv3r-c5h8-f4g5 (critical) — @zereight/mcp-gitlab: Unauthenticated arbitrary file read via `upload_markdown` enables PAT exfiltration and full account takeover
[GHSA] GHSA-cv3r-c5h8-f4g5 (critical) — @zereight/mcp-gitlab: Unauthenticated arbitrary file read via `upload_markdown` enables PAT exfiltration and full account takeover
GHSA-cv3r-c5h8-f4g5 Severity: critical CVE: CVE-2026-61560
@zereight/mcp-gitlab: Unauthenticated arbitrary file read via `upload_markdown` enables PAT exfiltration and full account takeover
### Summary
The SSE transport mode (`SSE=true`) exposes all MCP tools without any authentication. The `upload_markdown` tool reads arbitrary files from the server's local filesystem via an unsanitized `file_
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-61560cve
Original source: https://github.com/advisories/GHSA-cv3r-c5h8-f4g5