是一个用于 GitLab 的 Model Context Protocol(MCP)服务器。2.1.30 版本之前的版本在 Streamable HTTP MCP 端点处未设置有效的 Host 或 Origin 白名单。恶意网页可以利用 DNS 重绑定(DNS Rebinding)技术,将浏览器的请求路由到受害者本地的 MCP 监听服务,同时保留攻击者控制的 和 头。服务器会接受这些头信息,并进入 MCP 初始化流程,而不是在 HTTP 边界处直接拒绝请求。2.1.30 版本已包含针对此问题的修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| zereight | gitlab-mcp | < 2.1.30 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-61560 | 9.8 CRITICAL | @zereight/mcp-gitlab's unauthenticated arbitrary file read via `upload_markdown` enables P |
| CVE-2026-61559 | 9.6 CRITICAL | @zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery |
No comments yet