CVE-2026-61560
@zereight/mcp-gitlab is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the SSE transport mode (SSE=true) exposes all MCP tools without any authentication. The upload_markdown tool reads arbitrary files from the server's local filesystem via an unsanitized file_path parameter and uploads them to a GitLab project. Combined, any unauthenticated network-reachable attacker can read /proc/self/environ to steal the server's GITLABPERSONALACCESS_TOKEN and achieve full GitLab account takeover. This is the default configuration for Docker deployments. Version 2.1.27 contains a patch.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61560.json, https://github.com/zereight/gitlab-mcp/security/advisories/GHSA-cv3r-c5h8-f4g5, https://nvd.nist.gov/vuln/detail/CVE-2026-61560, https://github.com/zereight/gitlab-mcp/pull/482, https://github.com/zereight/gitlab-mcp/pull/554, https://github.com/zereight/gitlab-mcp/pull/622