CVE-2026-61462
mcp-gitlab contains a path traversal vulnerability in the jobid parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints. Attackers can supply crafted jobid values like ../../../user to escape the intended path prefix and access arbitrary GitLab API resources using the operator's personal access token.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61462.json, https://nvd.nist.gov/vuln/detail/CVE-2026-61462, https://www.vulncheck.com/advisories/mcp-gitlab-path-traversal-via-job-id-parameter, https://github.com/zereight/gitlab-mcp/issues/587, https://github.com/zereight/gitlab-mcp/commit/e2a81a047ab8750fa5bfa1763b5d85e5616f3994, https://github.com/zereight/gitlab-mcp