Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a critical vulnerability in a GitLab integration component that, when improperly configured, allows unauthenticated attackers to access sensitive server information, potentially leading to full account takeover. The default settings for Docker deployments are particularly susceptible.
- Unauthenticated access can expose sensitive server secrets.
- Default configurations for common deployments are affected.
- Confirm relevance and assess potential exposure.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker on the network can access the `@zereight/mcp-gitlab` server when it's configured with SSE transport enabled, which is the default in Docker deployments. This exposure allows them to use the `upload_markdown` tool to read sensitive files, such as `/proc/self/environ`. By obtaining the `GITLAB_PERSONAL_ACCESS_TOKEN` from this file, the attacker can then gain complete control over a GitLab account.
- Network-reachable unauthenticated access.
- Upload Markdown tool with unsanitized file path.
- Full GitLab account takeover.
Live Threat
Current exploitation, exposure, and threat context
The `@zereight/mcp-gitlab` component, when configured with SSE transport mode, could expose sensitive environment variables, including GitLab Personal Access Tokens, without authentication. This allows an attacker to read files from the server's local filesystem, potentially leading to a full GitLab account takeover. This is the default configuration for Docker deployments.
- Server environment variables, including tokens.
- Arbitrary file reads via unsanitized parameter.
- Full GitLab account takeover possible.
Operational Fix
Recommended remediation, mitigation, and detection steps
The `@zereight/mcp-gitlab` component, particularly in default Docker deployments, presents a critical risk due to unauthenticated access to sensitive GitLab tokens. Teams responsible for GitLab instances, containerized environments, and API integrations should prioritize identifying affected systems. The immediate first step is to determine the presence of this component, assess its network exposure and business criticality, and then identify the accountable owner to plan a coordinated remediation.
- Incident owners: GitLab administrators and platform engineers.
- Verify first: Network exposure and configuration of SSE transport.
- Action: Plan for configuration update or upgrade.