CVE-2026-61560
Deferred Deferred - Pending Action

Unauthenticated File Read in zereight mcp-gitlab

Vulnerability report for CVE-2026-61560, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-30

Assigner: GitHub, Inc.

Description

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the SSE transport mode (`SSE=true`) exposes all MCP tools without any authentication. The `upload_markdown` tool reads arbitrary files from the server's local filesystem via an unsanitized `file_path` parameter and uploads them to a GitLab project. Combined, any unauthenticated network-reachable attacker can read `/proc/self/environ` to steal the server's `GITLAB_PERSONAL_ACCESS_TOKEN` and achieve full GitLab account takeover. This is the default configuration for Docker deployments. Version 2.1.27 contains a patch.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-30
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-05
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zereight mcp-gitlab to 2.1.27 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability in @zereight/mcp-gitlab versions before 2.1.27 allows unauthenticated attackers to access MCP tools via the SSE transport mode. The upload_markdown tool can read arbitrary files from the server's filesystem using an unsanitized file_path parameter and upload them to a GitLab project. Attackers can exploit this to read /proc/self/environ and steal the GITLAB_PERSONAL_ACCESS_TOKEN, leading to full GitLab account takeover.

Detection Guidance

Check if the @zereight/mcp-gitlab server is running with SSE transport mode enabled (SSE=true). Verify if the server is exposed to unauthenticated network access. Inspect Docker deployments for default configurations. Look for unauthorized file uploads or suspicious activity in GitLab projects.

Impact Analysis

Unauthenticated attackers can gain full control of your GitLab account by stealing the personal access token. This could lead to unauthorized access to repositories, sensitive data exposure, code manipulation, or disruption of services. Docker deployments are particularly vulnerable as this is the default configuration.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection principles and HIPAA's security requirements. It may result in data breaches, unauthorized disclosures, or loss of control over personal or health information, potentially leading to legal penalties and compliance failures.

Mitigation Strategies

Upgrade @zereight/mcp-gitlab to version 2.1.27 or later. Disable SSE transport mode if not required. Restrict network access to the server. Rotate the GITLAB_PERSONAL_ACCESS_TOKEN if exposed. Review GitLab projects for unauthorized uploads.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-61560. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart