Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-cv3r-c5h8-f4g5
  • npm/@zereight/mcp-gitlab
@zereight/mcp-gitlab: Unauthenticated arbitrary file read via `upload_markdown` enables PAT exfiltration and full account takeover 16 Sep
  • Fix available
  • Severity - 9.8 (Critical)
GHSA-2h44-8472-frjj
  • npm/@zereight/mcp-gitlab
@zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery 15 Sep
  • Fix available
  • Severity - 9.6 (Critical)
GHSA-vmp7-252j-cwp7
  • npm/@zereight/mcp-gitlab
@zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport 15 Sep
  • Fix available
  • Severity - 9.6 (Critical)
GHSA-5648-rgj9-v224
  • npm/@zereight/mcp-gitlab
@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS 15 Sep
  • Fix available
  • Severity - 8.1 (High)