Browse all 4 CVE security advisories affecting zereight. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-61560 | @zereight/mcp-gitlab's unauthenticated arbitrary file read via `upload_markdown` enables PAT exfiltration and full account takeover — gitlab-mcp CWE-22 | 9.8 | Critical | 2026-09-15 |
| CVE-2026-61559 | @zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery — gitlab-mcp CWE-918 | 9.6 | Critical | 2026-09-15 |
| CVE-2026-61568 | @zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport — gitlab-mcp CWE-350 | 9.6 | Critical | 2026-09-15 |
| CVE-2026-61462 | mcp-gitlab Path Traversal via job_id Parameter — mcp-gitlab CWE-73 | 8.6 | High | 2026-07-13 |
This page lists every published CVE security advisory associated with zereight. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.