{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/mcp-gitlab--0.0.1--2.1.27/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:zereight:mcp-gitlab:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.6,"id":"CVE-2026-61559"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["mcp-gitlab (\u003e= 0.0.1, \u003c= 2.1.27)","mcp-gitlab (\u003c 2.1.30)","mcp-gitlab (\u003c 2.1.27)"],"_cs_severities":["critical"],"_cs_tags":["dns-rebinding","mcp","gitlab","cve-2026-61568","vulnerability","rce","exfiltration"],"_cs_type":"advisory","_cs_vendors":["zereight"],"content_html":"\u003cp\u003eThe npm package @zereight/mcp-gitlab contains a critical SSRF vulnerability (CVE-2026-61559) in all versions through commit 74a8c83. When the configuration variable \u003ccode\u003eENABLE_DYNAMIC_API_URL\u003c/code\u003e is set to \u003ccode\u003etrue\u003c/code\u003e, the application blindly trusts the \u003ccode\u003eX-GitLab-API-URL\u003c/code\u003e HTTP header provided by a requester. The server validates that the header is a well-formed URL but fails to perform any allowlist check or hostname restriction against the destination.\u003c/p\u003e\n\u003cp\u003eAs a result, an attacker can supply an arbitrary URL via this header. The server subsequently uses this URL for downstream GitLab API calls, attaching the victim's \u003ccode\u003ePrivate-Token\u003c/code\u003e header to the request before sending it to the attacker-controlled server. This flaw allows attackers to steal credentials and gain full authenticated access to the victim's GitLab account, including CI/CD variables, source code, and project management data. The vulnerability is reachable in multi-user deployment scenarios where \u003ccode\u003eREMOTE_AUTHORIZATION=true\u003c/code\u003e is enabled.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe target is running \u003ccode\u003emcp-gitlab\u003c/code\u003e with \u003ccode\u003eENABLE_DYNAMIC_API_URL=true\u003c/code\u003e and \u003ccode\u003eREMOTE_AUTHORIZATION=true\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe attacker initializes a listener on an external server capable of capturing HTTP headers.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious request to the MCP server's tool execution endpoint.\u003c/li\u003e\n\u003cli\u003eThe attacker injects the \u003ccode\u003eX-GitLab-API-URL\u003c/code\u003e header pointing to their listener URL.\u003c/li\u003e\n\u003cli\u003eThe MCP server process parses the malicious header and updates the API base URL for the current session.\u003c/li\u003e\n\u003cli\u003eThe server initiates a legitimate GitLab API call (e.g., to list issues) using the attacker-supplied URL.\u003c/li\u003e\n\u003cli\u003eThe server attaches the victim's \u003ccode\u003ePrivate-Token\u003c/code\u003e to the request, facilitating the SSRF-based exfiltration.\u003c/li\u003e\n\u003cli\u003eThe attacker receives the victim's token via their listener and proceeds to exfiltrate or manipulate GitLab resources.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full account compromise at the victim's permission level. Attackers can gain unauthorized access to all repositories, issues, and merge requests, as well as read and modify CI/CD pipelines, secrets, and environment variables. This represents a complete breach of the GitLab security domain for the affected user.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eIf using \u003ccode\u003emcp-gitlab\u003c/code\u003e in a multi-user environment, disable \u003ccode\u003eENABLE_DYNAMIC_API_URL\u003c/code\u003e immediately until a patched version is available.\u003c/li\u003e\n\u003cli\u003eImplement an allowlist for the \u003ccode\u003eX-GitLab-API-URL\u003c/code\u003e header by verifying the hostname against a hardcoded list of trusted GitLab instances before the request is processed.\u003c/li\u003e\n\u003cli\u003eSearch web access logs for any incoming requests containing the \u003ccode\u003eX-GitLab-API-URL\u003c/code\u003e header to identify potential exploitation attempts.\u003c/li\u003e\n\u003cli\u003eRotate all GitLab Personal Access Tokens and CI/CD job tokens for users who interacted with an affected instance of the MCP server.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-16T19:07:21Z","date_published":"2026-09-16T01:04:47Z","id":"https://feed.craftedsignal.io/briefs/2026-09-mcp-gitlab-ssrf/","summary":"The mcp-gitlab server is vulnerable to Server-Side Request Forgery (SSRF) when ENABLE_DYNAMIC_API_URL is enabled, allowing attackers to force the server to forward victim GitLab tokens to an arbitrary host.","title":"SSRF Vulnerability in mcp-gitlab Enables GitLab Credential Theft","url":"https://feed.craftedsignal.io/briefs/2026-09-mcp-gitlab-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Mcp-Gitlab (\u003e= 0.0.1, \u003c= 2.1.27)","version":"https://jsonfeed.org/version/1.1"}