CVE-2026-61462
Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
13/07/2026
Last modified:
13/07/2026
Description
mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints. Attackers can supply crafted job_id values like ../../../user to escape the intended path prefix and access arbitrary GitLab API resources using the operator's personal access token.
Impact
Base Score 4.0
9.20
Severity 4.0
CRITICAL
Base Score 3.x
8.60
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://github.com/zereight/gitlab-mcp
- https://github.com/zereight/gitlab-mcp/commit/e2a81a047ab8750fa5bfa1763b5d85e5616f3994
- https://github.com/zereight/gitlab-mcp/issues/587
- https://www.vulncheck.com/advisories/mcp-gitlab-path-traversal-via-job-id-parameter
- https://github.com/zereight/gitlab-mcp/issues/587



