Model Context Protocol Server Vulnerability in GitLab by Zereight
CVE-2026-61568

9.6CRITICAL

Key Information:

Vendor

Zereight

Vendor
CVE Published:
15 September 2026

What is CVE-2026-61568?

The Model Context Protocol server for GitLab, @zereight/mcp-gitlab, has a vulnerability in versions prior to 2.1.30 that allows a malicious web page to exploit the Streamable HTTP MCP endpoint. This security flaw occurs due to the absence of an effective Host or Origin allowlist, permitting an attacker to utilize DNS rebinding techniques. By routing browser requests to the victim's local MCP listener with manipulated headers, the server may inadvertently process requests that should be rejected, allowing potential unauthorized access. The issue has been patched in version 2.1.30.

Affected Version(s)

gitlab-mcp < 2.1.30

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.