Horizon Alert
Summary of the vulnerability and why it matters
The `@zereight/mcp-gitlab` component, used as a Model Context Protocol server for GitLab, has a vulnerability that could allow an attacker to intercept sensitive tokens. If a specific environment variable is enabled, the server may be tricked into sending user authentication tokens to malicious external servers when processing requests. This could lead to unauthorized access and data compromise within the GitLab environment.
- Sensitive GitLab tokens may be exposed to attackers.
- This impacts backend services that bridge AI and GitLab.
- Confirm if your environment uses this specific integration.
Attack Path
How an attacker could exploit the issue
An attacker can target the GitLab Model Context Protocol server by sending a specially crafted HTTP request. If the server is configured with dynamic API URLs enabled, the attacker can manipulate the `X-GitLab-API-URL` header to redirect the server's subsequent API calls to an attacker-controlled host. This allows the attacker to intercept the victim's authentication token, which is automatically included in these redirected calls.
- Requires network access to the HTTP transport.
- Triggered by a malicious `X-GitLab-API-URL` header.
- Leaks victim's private token to attacker.
Live Threat
Current exploitation, exposure, and threat context
When the `ENABLE_DYNAMIC_API_URL` environment variable is set to true, a vulnerable `@zereight/mcp-gitlab` server could be tricked into sending a user's GitLab Private-Token to an attacker-controlled server. This occurs if an attacker can influence the `X-GitLab-API-URL` header in an HTTP request. The server then uses this controlled URL for subsequent API calls within that request, unknowingly sending the sensitive token.
- GitLab private tokens.
- Malicious `X-GitLab-API-URL` header.
- Token theft and potential account compromise.
Operational Fix
Recommended remediation, mitigation, and detection steps
Determine ownership by confirming where the `@zereight/mcp-gitlab` server is deployed, assess its exposure and business criticality, and then plan remediation based on the identified risk.
- Application owners should manage remediation.
- Verify network reachability and asset criticality.
- Plan updates during the next maintenance window.