CVE-2026-61559
Deferred Deferred - Pending Action

SSRF via Unrestricted API URL in zereight/mcp-gitlab

Vulnerability report for CVE-2026-61559, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-30

Assigner: GitHub, Inc.

Description

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1.27, when the environment variable `ENABLE_DYNAMIC_API_URL=true` is set, the server reads the `X-GitLab-API-URL` HTTP request header and uses it as the base URL for all outbound GitLab API calls made within that request. The server validates that the value is a well-formed URL (`new URL(dynamicApiUrl)`) but applies no allowlist or hostname restriction. The server then attaches the victim's `Private-Token` to every outbound fetch that uses the redirected URL. Any caller who can reach the HTTP transport can set `X-GitLab-API-URL` to an attacker-controlled host. The next GitLab API call the server makes delivers the victim's token to that host. Version 2.1.27 contains a patch.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-30
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zereight mcp-gitlab to 2.1.27 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the @zereight/mcp-gitlab package. When the environment variable ENABLE_DYNAMIC_API_URL is set to true, the server reads the X-GitLab-API-URL HTTP header to determine the base URL for GitLab API calls. It validates the URL format but does not restrict which hostnames can be used. An attacker who can send HTTP requests to the server can set this header to their own server, causing the victim's Private-Token to be sent to the attacker's server during subsequent API calls.

Detection Guidance

Check if the environment variable ENABLE_DYNAMIC_API_URL=true is set in the @zereight/mcp-gitlab server configuration. Monitor HTTP headers for the X-GitLab-API-URL header being used to redirect API calls. Inspect network traffic for outbound requests to unexpected hosts.

Impact Analysis

If you use this package with ENABLE_DYNAMIC_API_URL=true, an attacker could steal your GitLab Private-Token by intercepting API calls. This token could grant the attacker access to your GitLab repositories, issues, and other sensitive data. The high CVSS score (9.6) indicates a critical risk of unauthorized access and data exposure.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection principles and HIPAA's security requirements for protected health information. Organizations using this package may face compliance violations, legal penalties, and reputational damage if tokens or data are exposed.

Mitigation Strategies

Upgrade @zereight/mcp-gitlab to version 2.1.27 or later. Disable the ENABLE_DYNAMIC_API_URL environment variable if not required. Implement network-level restrictions to block unauthorized outbound requests to external hosts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-61559. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart