@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS
@zereight/mcp-gitlab version prior to 2.1.30 contains multiple security flaws that bypass key safety controls such as read-only mode, project allow-list, and transport authentication. These include a GraphQL mutation bypass that allows unauthorized writes, unauthenticated access to HTTP and SSE transports, a session exhaustion denial-of-service, and exposure of CI job traces that can be manipulated by attackers. These vulnerabilities enable attackers with access to the MCP server port or a semi-trusted client to perform unauthorized GitLab writes, access GitLab credentials without authentication, and cause denial of service.
AI Analysis
Technical Summary
@zereight/mcp-gitlab relies on read-only mode, a project allow-list, and transport authentication to protect GitLab access. Five distinct flaws defeat these controls: (F1) execute_graphql incorrectly detects write operations allowing mutations despite read-only mode and bypassing project allow-list restrictions; (F2) the /mcp HTTP endpoint is unauthenticated under certain credential configurations; (F3) server-sent events (SSE) transport lacks authentication and DNS rebinding protections; (F4) session token validation is weak, allowing unauthenticated session exhaustion DoS; (F5) CI job traces are returned verbatim, enabling prompt injection attacks. These issues were identified in version 2.1.28 and earlier, with no known exploits in the wild. The CVSS 3.1 base score is 8.1 (high severity).
Potential Impact
An attacker or a prompt-injected agent can perform arbitrary GitLab write operations despite the server being configured as read-only and bypass project allow-list restrictions, limited only by the token's privileges. Unauthenticated attackers can access the MCP server's GitLab credentials via unauthenticated HTTP and SSE transports, potentially enabling unauthorized actions. Additionally, attackers can exhaust session capacity causing denial of service to legitimate users. CI job logs returned verbatim can be manipulated to influence the agent's behavior, potentially escalating the impact.
Mitigation Recommendations
A patch is available for @zereight/mcp-gitlab addressing these issues in versions 2.1.30 and later. Operators should upgrade to version 2.1.30 or newer to remediate these vulnerabilities. Until patched, restrict network access to the MCP server port to trusted clients only and avoid configurations that enable unauthenticated transports. Review and apply vendor guidance for secure deployment and authentication settings.
@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS
Description
@zereight/mcp-gitlab version prior to 2.1.30 contains multiple security flaws that bypass key safety controls such as read-only mode, project allow-list, and transport authentication. These include a GraphQL mutation bypass that allows unauthorized writes, unauthenticated access to HTTP and SSE transports, a session exhaustion denial-of-service, and exposure of CI job traces that can be manipulated by attackers. These vulnerabilities enable attackers with access to the MCP server port or a semi-trusted client to perform unauthorized GitLab writes, access GitLab credentials without authentication, and cause denial of service.
CVSS v3.1
Score 8.1high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
@zereight/mcp-gitlab relies on read-only mode, a project allow-list, and transport authentication to protect GitLab access. Five distinct flaws defeat these controls: (F1) execute_graphql incorrectly detects write operations allowing mutations despite read-only mode and bypassing project allow-list restrictions; (F2) the /mcp HTTP endpoint is unauthenticated under certain credential configurations; (F3) server-sent events (SSE) transport lacks authentication and DNS rebinding protections; (F4) session token validation is weak, allowing unauthenticated session exhaustion DoS; (F5) CI job traces are returned verbatim, enabling prompt injection attacks. These issues were identified in version 2.1.28 and earlier, with no known exploits in the wild. The CVSS 3.1 base score is 8.1 (high severity).
Potential Impact
An attacker or a prompt-injected agent can perform arbitrary GitLab write operations despite the server being configured as read-only and bypass project allow-list restrictions, limited only by the token's privileges. Unauthenticated attackers can access the MCP server's GitLab credentials via unauthenticated HTTP and SSE transports, potentially enabling unauthorized actions. Additionally, attackers can exhaust session capacity causing denial of service to legitimate users. CI job logs returned verbatim can be manipulated to influence the agent's behavior, potentially escalating the impact.
Mitigation Recommendations
A patch is available for @zereight/mcp-gitlab addressing these issues in versions 2.1.30 and later. Operators should upgrade to version 2.1.30 or newer to remediate these vulnerabilities. Until patched, restrict network access to the MCP server port to trusted clients only and avoid configurations that enable unauthenticated transports. Review and apply vendor guidance for secure deployment and authentication settings.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-5648-rgj9-v224
- Osv Schema Version
- 1.4.0
- Ecosystems
- ["npm"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6aaa082055bf5e2cf5ea5584
Added to database: 09/16/2026, 03:08:16 UTC
Last enriched: 09/16/2026, 05:10:13 UTC
Last updated: 09/16/2026, 05:10:13 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.