Skip to main content

@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS

0
High
Published: 09/15/2026 (09/15/2026, 20:48:22 UTC)
Source: GCVE Database
Product: @zereight/mcp-gitlab

Description

@zereight/mcp-gitlab version prior to 2.1.30 contains multiple security flaws that bypass key safety controls such as read-only mode, project allow-list, and transport authentication. These include a GraphQL mutation bypass that allows unauthorized writes, unauthenticated access to HTTP and SSE transports, a session exhaustion denial-of-service, and exposure of CI job traces that can be manipulated by attackers. These vulnerabilities enable attackers with access to the MCP server port or a semi-trusted client to perform unauthorized GitLab writes, access GitLab credentials without authentication, and cause denial of service.

CVSS v3.1

Score 8.1high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Affected software

npmghsa
@zereight/mcp-gitlab
Affected versions
<2.1.30

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/16/2026, 05:10:13 UTC

Technical Analysis

@zereight/mcp-gitlab relies on read-only mode, a project allow-list, and transport authentication to protect GitLab access. Five distinct flaws defeat these controls: (F1) execute_graphql incorrectly detects write operations allowing mutations despite read-only mode and bypassing project allow-list restrictions; (F2) the /mcp HTTP endpoint is unauthenticated under certain credential configurations; (F3) server-sent events (SSE) transport lacks authentication and DNS rebinding protections; (F4) session token validation is weak, allowing unauthenticated session exhaustion DoS; (F5) CI job traces are returned verbatim, enabling prompt injection attacks. These issues were identified in version 2.1.28 and earlier, with no known exploits in the wild. The CVSS 3.1 base score is 8.1 (high severity).

Potential Impact

An attacker or a prompt-injected agent can perform arbitrary GitLab write operations despite the server being configured as read-only and bypass project allow-list restrictions, limited only by the token's privileges. Unauthenticated attackers can access the MCP server's GitLab credentials via unauthenticated HTTP and SSE transports, potentially enabling unauthorized actions. Additionally, attackers can exhaust session capacity causing denial of service to legitimate users. CI job logs returned verbatim can be manipulated to influence the agent's behavior, potentially escalating the impact.

Mitigation Recommendations

A patch is available for @zereight/mcp-gitlab addressing these issues in versions 2.1.30 and later. Operators should upgrade to version 2.1.30 or newer to remediate these vulnerabilities. Until patched, restrict network access to the MCP server port to trusted clients only and avoid configurations that enable unauthenticated transports. Review and apply vendor guidance for secure deployment and authentication settings.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-5648-rgj9-v224
Osv Schema Version
1.4.0
Ecosystems
["npm"]
Database Specific Severity
HIGH
Cvss Version
3.1

Threat ID: 6aaa082055bf5e2cf5ea5584

Added to database: 09/16/2026, 03:08:16 UTC

Last enriched: 09/16/2026, 05:10:13 UTC

Last updated: 09/16/2026, 05:10:13 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses