ADVISORYCRITICAL6h ago · Sep 16, 2026
CRITICAL: @zereight/mcp-gitlab — @zereight/mcp-gitlab: Unauthenticated arbitrary file read via `upload_markdown` enables PAT exfiltration and full account takeover

The SSE transport mode (SSE=true) exposes all MCP tools without any authentication. The uploadmarkdown tool reads arbitrary files from the server's local filesystem via an unsanitized filepath parameter and uploads them to a GitLab project.…
Read it at @zereight/mcp-gitlab