Model Context Protocol Server Vulnerability in GitLab by Zereight
CVE-2026-61568
9.6CRITICAL
What is CVE-2026-61568?
The Model Context Protocol server for GitLab, @zereight/mcp-gitlab, has a vulnerability in versions prior to 2.1.30 that allows a malicious web page to exploit the Streamable HTTP MCP endpoint. This security flaw occurs due to the absence of an effective Host or Origin allowlist, permitting an attacker to utilize DNS rebinding techniques. By routing browser requests to the victim's local MCP listener with manipulated headers, the server may inadvertently process requests that should be rejected, allowing potential unauthorized access. The issue has been patched in version 2.1.30.
Affected Version(s)
gitlab-mcp < 2.1.30
