External risk intelligence

Unauthenticated File Read in @zereight/mcp-gitlab Allows GitLab Account Takeover.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-61560

The component is a Model Context Protocol server that enables external integration with GitLab. The bulletin explicitly identifies the vulnerable SSE transport mode as the default configuration for Docker deployments, making this a service that is commonly exposed as a network-reachable interface for agent-based workflows.

Path Traversal

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in a GitLab integration component that, when improperly configured, allows unauthenticated attackers to access sensitive server information, potentially leading to full account takeover. The default settings for Docker deployments are particularly susceptible.

  • Unauthenticated access can expose sensitive server secrets.
  • Default configurations for common deployments are affected.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker on the network can access the `@zereight/mcp-gitlab` server when it's configured with SSE transport enabled, which is the default in Docker deployments. This exposure allows them to use the `upload_markdown` tool to read sensitive files, such as `/proc/self/environ`. By obtaining the `GITLAB_PERSONAL_ACCESS_TOKEN` from this file, the attacker can then gain complete control over a GitLab account.

  • Network-reachable unauthenticated access.
  • Upload Markdown tool with unsanitized file path.
  • Full GitLab account takeover.

Live Threat

Current exploitation, exposure, and threat context

The `@zereight/mcp-gitlab` component, when configured with SSE transport mode, could expose sensitive environment variables, including GitLab Personal Access Tokens, without authentication. This allows an attacker to read files from the server's local filesystem, potentially leading to a full GitLab account takeover. This is the default configuration for Docker deployments.

  • Server environment variables, including tokens.
  • Arbitrary file reads via unsanitized parameter.
  • Full GitLab account takeover possible.

Operational Fix

Recommended remediation, mitigation, and detection steps

The `@zereight/mcp-gitlab` component, particularly in default Docker deployments, presents a critical risk due to unauthenticated access to sensitive GitLab tokens. Teams responsible for GitLab instances, containerized environments, and API integrations should prioritize identifying affected systems. The immediate first step is to determine the presence of this component, assess its network exposure and business criticality, and then identify the accountable owner to plan a coordinated remediation.

  • Incident owners: GitLab administrators and platform engineers.
  • Verify first: Network exposure and configuration of SSE transport.
  • Action: Plan for configuration update or upgrade.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is @zereight/mcp-gitlab?

It is a server component designed for the Model Context Protocol that allows AI agents to interact directly with GitLab projects. Developers use it to bridge automated workflows with GitLab tasks, such as managing repositories or issues. Because it is often deployed via Docker, it frequently runs as a network-accessible service to support these integrated, agent-based activities.

What does CWE-22 mean for CVE-2026-61560?

This vulnerability involves Improper Limitation of a Pathname to a Restricted Directory, commonly known as Path Traversal (CWE-22). In this context, the server fails to properly sanitize input, allowing the software to read files outside of its intended scope. An attacker can exploit this weakness to access sensitive system files that should remain private, rather than just the specific data requested.

How can an attacker trigger this vulnerability?

An attacker needs network access to an affected server running with the SSE transport mode enabled. If the server is in this mode, no authentication is required to use its tools. A request is not triggered by standard operations alone; it requires specifically sending commands to the `upload_markdown` tool that abuse the path parameter to retrieve unintended files from the local filesystem.

How do I know if my system is at risk?

Halo Surface Signal indicates that because the SSE transport mode is the default for Docker deployments, this server is often exposed as a network-reachable interface. If your instance is reachable over the network and has not been updated, it is likely vulnerable. You should check your deployment configuration to see if SSE is active and if the service is accessible to unauthorized network users.

What should I do to secure my environment?

First, identify all instances of this component within your infrastructure to assess their network exposure. Once located, coordinate with the responsible platform engineers to verify if the SSE transport mode is currently active. The primary fix is to update the software to version 2.1.27 or higher, which includes a patch to address the underlying vulnerability.

References