External risk intelligence

GitLab MCP Server Token Leak Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-61559

This is a Model Context Protocol (MCP) server, which acts as a bridge between AI models and internal GitLab instances. While it is network-reachable and processes HTTP requests, it is typically deployed as a backend utility or integration component for local or internal AI tools, not as a public-facing web service or edge gateway.

Server-Side Request Forgery

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

The `@zereight/mcp-gitlab` component, used as a Model Context Protocol server for GitLab, has a vulnerability that could allow an attacker to intercept sensitive tokens. If a specific environment variable is enabled, the server may be tricked into sending user authentication tokens to malicious external servers when processing requests. This could lead to unauthorized access and data compromise within the GitLab environment.

  • Sensitive GitLab tokens may be exposed to attackers.
  • This impacts backend services that bridge AI and GitLab.
  • Confirm if your environment uses this specific integration.

Attack Path

How an attacker could exploit the issue

An attacker can target the GitLab Model Context Protocol server by sending a specially crafted HTTP request. If the server is configured with dynamic API URLs enabled, the attacker can manipulate the `X-GitLab-API-URL` header to redirect the server's subsequent API calls to an attacker-controlled host. This allows the attacker to intercept the victim's authentication token, which is automatically included in these redirected calls.

  • Requires network access to the HTTP transport.
  • Triggered by a malicious `X-GitLab-API-URL` header.
  • Leaks victim's private token to attacker.

Live Threat

Current exploitation, exposure, and threat context

When the `ENABLE_DYNAMIC_API_URL` environment variable is set to true, a vulnerable `@zereight/mcp-gitlab` server could be tricked into sending a user's GitLab Private-Token to an attacker-controlled server. This occurs if an attacker can influence the `X-GitLab-API-URL` header in an HTTP request. The server then uses this controlled URL for subsequent API calls within that request, unknowingly sending the sensitive token.

  • GitLab private tokens.
  • Malicious `X-GitLab-API-URL` header.
  • Token theft and potential account compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

Determine ownership by confirming where the `@zereight/mcp-gitlab` server is deployed, assess its exposure and business criticality, and then plan remediation based on the identified risk.

  • Application owners should manage remediation.
  • Verify network reachability and asset criticality.
  • Plan updates during the next maintenance window.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is @zereight/mcp-gitlab?

@zereight/mcp-gitlab is a Model Context Protocol server. It acts as a specialized bridge, allowing AI models to interact with and retrieve information from GitLab instances, essentially helping AI agents perform tasks or gather context from your software development environment.

What does CWE-918 mean for CVE-2026-61559?

This CVE involves CWE-918, or Server-Side Request Forgery (SSRF). In plain terms, the server can be tricked into making requests to a location chosen by an attacker. Because the server does not restrict where it sends data, it inadvertently forwards sensitive authentication tokens to an external host controlled by the attacker instead of the intended GitLab API.

How is this vulnerability triggered?

An attacker triggers this by sending a request with a specific HTTP header, X-GitLab-API-URL, when the server has the ENABLE_DYNAMIC_API_URL setting enabled. The vulnerability does not occur if this environment variable is set to false, as the server will not honor the redirected URL header.

Is my instance reachable from the internet?

According to Halo Surface Signal, this component is usually a backend integration for local or internal AI tools, not a public-facing service. However, because it processes HTTP requests, if it is reachable over your network, an attacker with that same network access could potentially send the malicious header to exploit the server.

How do I secure my GitLab MCP server?

First, confirm if your environment is using @zereight/mcp-gitlab and check if the ENABLE_DYNAMIC_API_URL environment variable is active. If so, update the software to version 2.1.27 or later, which contains the necessary patch to prevent unauthorized URL redirection.

References