CVE-2026-61559: CWE-918: Server-Side Request Forgery (SSRF) in zereight gitlab-mcp
`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1.27, when the environment variable `ENABLE_DYNAMIC_API_URL=true` is set, the server reads the `X-GitLab-API-URL` HTTP request header and uses it as the base URL for all outbound GitLab API calls made within that request. The server validates that the value is a well-formed URL (`new URL(dynamicApiUrl)`) but applies no allowlist or hostname restriction. The server then attaches the victim's `Private-Token` to every outbound fetch that uses the redirected URL. Any caller who can reach the HTTP transport can set `X-GitLab-API-URL` to an attacker-controlled host. The next GitLab API call the server makes delivers the victim's token to that host. Version 2.1.27 contains a patch.
AI Analysis
Technical Summary
The zereight gitlab-mcp server, when configured with ENABLE_DYNAMIC_API_URL=true, reads the X-GitLab-API-URL HTTP header and uses it as the base URL for outbound GitLab API calls. Although the URL is validated for proper format, there is no allowlist or hostname restriction, enabling an attacker who can send HTTP requests to the server to redirect API calls to an attacker-controlled host. The server attaches the victim's Private-Token to these requests, potentially exposing sensitive credentials. This SSRF vulnerability is identified as CWE-918 and has a CVSS 3.1 score of 9.6 (critical). The issue is fixed in version 2.1.27.
Potential Impact
An attacker able to send HTTP requests with a crafted X-GitLab-API-URL header can cause the server to send the victim's Private-Token to an attacker-controlled host. This leads to disclosure of sensitive authentication tokens, compromising confidentiality and integrity of the victim's GitLab API access. There is no reported active exploitation in the wild.
Mitigation Recommendations
Upgrade zereight gitlab-mcp to version 2.1.27 or later, where this vulnerability is patched. If upgrading is not immediately possible, disable the ENABLE_DYNAMIC_API_URL environment variable to prevent the server from using the X-GitLab-API-URL header for outbound API calls. Avoid relying on untrusted input for API endpoint URLs.
CVE-2026-61559: CWE-918: Server-Side Request Forgery (SSRF) in zereight gitlab-mcp
Description
`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1.27, when the environment variable `ENABLE_DYNAMIC_API_URL=true` is set, the server reads the `X-GitLab-API-URL` HTTP request header and uses it as the base URL for all outbound GitLab API calls made within that request. The server validates that the value is a well-formed URL (`new URL(dynamicApiUrl)`) but applies no allowlist or hostname restriction. The server then attaches the victim's `Private-Token` to every outbound fetch that uses the redirected URL. Any caller who can reach the HTTP transport can set `X-GitLab-API-URL` to an attacker-controlled host. The next GitLab API call the server makes delivers the victim's token to that host. Version 2.1.27 contains a patch.
CVSS v3.1
Score 9.6critical
Affected software
zereight
gitlab-mcp
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The zereight gitlab-mcp server, when configured with ENABLE_DYNAMIC_API_URL=true, reads the X-GitLab-API-URL HTTP header and uses it as the base URL for outbound GitLab API calls. Although the URL is validated for proper format, there is no allowlist or hostname restriction, enabling an attacker who can send HTTP requests to the server to redirect API calls to an attacker-controlled host. The server attaches the victim's Private-Token to these requests, potentially exposing sensitive credentials. This SSRF vulnerability is identified as CWE-918 and has a CVSS 3.1 score of 9.6 (critical). The issue is fixed in version 2.1.27.
Potential Impact
An attacker able to send HTTP requests with a crafted X-GitLab-API-URL header can cause the server to send the victim's Private-Token to an attacker-controlled host. This leads to disclosure of sensitive authentication tokens, compromising confidentiality and integrity of the victim's GitLab API access. There is no reported active exploitation in the wild.
Mitigation Recommendations
Upgrade zereight gitlab-mcp to version 2.1.27 or later, where this vulnerability is patched. If upgrading is not immediately possible, disable the ENABLE_DYNAMIC_API_URL environment variable to prevent the server from using the X-GitLab-API-URL header for outbound API calls. Avoid relying on untrusted input for API endpoint URLs.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-07-10T16:48:39.923Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aa9b25a55bf5e2cf55e9558
Added to database: 09/15/2026, 21:02:18 UTC
Last enriched: 09/15/2026, 21:16:40 UTC
Last updated: 09/15/2026, 22:11:28 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.