Vendor
high
advisory
Multiple Safety-Control Bypasses in @zereight/mcp-gitlab
4 TTPsMultiple vulnerabilities in the @zereight/mcp-gitlab package allow attackers to bypass read-only mode, exfiltrate data, perform unauthorized GitLab operations, and trigger a denial-of-service via unauthenticated session exhaustion.
@zereight/mcp-gitlab
mcp
gitlab
llm-security
supply-chain
4t
critical
advisory
SSRF Vulnerability in mcp-gitlab Enables GitLab Credential Theft
1 rule 6 TTPs 1 CVEThe mcp-gitlab server is vulnerable to Server-Side Request Forgery (SSRF) when ENABLE_DYNAMIC_API_URL is enabled, allowing attackers to force the server to forward victim GitLab tokens to an arbitrary host.
mcp-gitlab +2
dns-rebinding
mcp
gitlab
cve-2026-61568
vulnerability
rce
exfiltration
1r
6t
1c
updated