ADVISORYCRITICAL23h ago · Sep 15, 2026
CRITICAL: @zereight/mcp-gitlab — @zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery

Server-Side Request Forgery via X-GitLab-API-URL Header Allows Credential Theft Affected - Repository: zereight/gitlab-mcp - Affected versions: All versions through commit 74a8c83 - Patched versions: None at time of report Severity High. CVSS v3.1 8.5…
Read it at @zereight/mcp-gitlab