All 3 CVE vulnerabilities found in gitlab-mcp, with AI-generated Chinese analysis, references, and POCs.
Vendor: zereight
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-61560 | @zereight/mcp-gitlab's unauthenticated arbitrary file read via `upload_markdown` enables PAT exfiltration and full account takeover CWE-22 | 9.8 | Critical | 2026-09-15 |
| CVE-2026-61559 | @zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery CWE-918 | 9.6 | Critical | 2026-09-15 |
| CVE-2026-61568 | @zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport CWE-350 | 9.6 | Critical | 2026-09-15 |
All 3 known CVE vulnerabilities affecting gitlab-mcp with full Chinese analysis, references, and POCs where available.