Model Context Protocol Server Vulnerability in GitLab by Zereight
CVE-2026-61559

9.6CRITICAL

Key Information:

Vendor

Zereight

Vendor
CVE Published:
15 September 2026

What is CVE-2026-61559?

The Model Context Protocol server for GitLab has a vulnerability where the server utilizes the X-GitLab-API-URL header for outgoing GitLab API calls without proper allowlisting or hostname restrictions. When ENABLE_DYNAMIC_API_URL is enabled, any malicious actor can craft a request that includes an attacker-controlled URL in this header. As a result, the server will send the authenticated user’s Private-Token to this unauthorized destination, potentially compromising sensitive information. This vulnerability was resolved in version 2.1.27.

Affected Version(s)

gitlab-mcp >= 0.0.1, < 2.1.27

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.