SCA: security update for @zereight/mcp-gitlab (GHSA-2h44-8472-frjj)

critical Tenable Self-Hosted Container Security Plugin ID 447994

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior
to version 2.1.27, when the environment variable `ENABLE_DYNAMIC_API_URL=true` is set, the server reads
the `X-GitLab-API-URL` HTTP request header and uses it as the base URL for all outbound GitLab API calls
made within that request. The server validates that the value is a well-formed URL (`new
URL(dynamicApiUrl)`) but applies no allowlist or hostname restriction. The server then attaches the
victim's `Private-Token` to every outbound fetch that uses the redirected URL. Any caller who can reach
the HTTP transport can set `X-GitLab-API-URL` to an attacker-controlled host. The next GitLab API call the
server makes delivers the victim's token to that host. Version 2.1.27 contains a patch. (CVE-2026-61559)

Solution

Update the @zereight/mcp-gitlab library and its related packages to version 2.1.27 or later.

See Also

https://github.com/advisories/GHSA-2h44-8472-frjj

Plugin Details

Severity: Critical

ID: 447994

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 9/16/2026

Updated: 9/16/2026

Risk Information

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: High

Base Score: 8.5

Temporal Score: 6.3

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:N

CVSS Score Source: CVE-2026-61559

CVSS v3

Risk Factor: Critical

Base Score: 9.6

Temporal Score: 8.3

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/15/2026

Vulnerability Publication Date: 9/15/2026

Reference Information

CVE: CVE-2026-61559

cwe: CWE-918