External risk intelligence

GitLab MCP Streamable HTTP Endpoint Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-61568

This vulnerability affects a Model Context Protocol (MCP) server typically running as a local-only listener for developer tools or local client integration. It is not designed to be exposed to the public internet, and its deployment pattern centers on local, internal communication between a client application and the local service.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in the `@zereight/mcp-gitlab` Model Context Protocol server for GitLab. If exploited, this issue could allow a malicious webpage to gain unauthorized access to internal systems, potentially impacting data confidentiality, integrity, and availability. The main concern is confirming if this specific technology is in use within our environment.

  • Server accepts malicious web requests.
  • Potential for unauthorized system access.
  • Confirm use and assess relevance.

Attack Path

How an attacker could exploit the issue

An attacker could trick a user into visiting a malicious webpage. This page would then leverage a DNS rebinding technique to make the user's browser send requests to a local service that unexpectedly trusts the requests based on attacker-controlled headers. This allows the attacker to reach the vulnerable MCP endpoint, leading to a compromise.

  • Requires user interaction.
  • Triggers by visiting a malicious webpage.
  • Allows critical data compromise.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, a malicious web page could leverage DNS rebinding to bypass HTTP security controls. This could allow an attacker-controlled `Host` and `Origin` to interact with a local Model Context Protocol server, potentially leading to unintended service behavior.

  • Local MCP listener service.
  • Via DNS rebinding and malicious web page.
  • Unintended service behavior.

Operational Fix

Recommended remediation, mitigation, and detection steps

The `@zereight/mcp-gitlab` server, used for local communication, may be vulnerable if not properly configured. The first step is to identify all instances of this technology, confirm their reachability and business criticality, and then determine the accountable owner for planning remediation.

  • Application and platform teams own the issue.
  • Verify MCP listener accessibility and business impact.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is @zereight/mcp-gitlab?

@zereight/mcp-gitlab is a server that implements the Model Context Protocol (MCP), a standard used to connect AI assistants and development tools to GitLab. It typically acts as a local bridge, allowing tools on a developer's machine to interact with GitLab repositories, issues, and other project data securely.

What does CWE-350 mean for CVE-2026-61568?

CWE-350 refers to Improper Authentication, which occurs when a system incorrectly verifies the identity of a user or the source of a request. In this CVE, the server fails to properly check the Host or Origin headers of incoming HTTP requests. Because these headers are trusted without validation, the server mistakenly allows unauthorized requests to access its initialization functions.

How does DNS rebinding trigger this vulnerability?

An attacker uses a malicious webpage to trick a user's browser into communicating with the local MCP service via DNS rebinding. This technique bypasses browser security by making the browser believe the attacker's site and the local service are the same. Simply running the service does not trigger the bug; the attacker specifically needs to manipulate the request headers while a user visits their site.

Do I need to worry if my service is internal?

Halo Surface Signal indicates that this service is typically intended for local-only use, making it very unlikely to be exposed directly to the public internet. However, because the attack relies on a user's browser acting as a proxy from an external malicious site to the internal local listener, it remains a concern for any machine where developers actively run this software.

How should I respond if I use this software?

Your first step is to locate all instances of @zereight/mcp-gitlab within your development environment. Once identified, verify if the installed version is earlier than 2.1.30. If it is, coordinate with the appropriate application or platform team to upgrade the software, as version 2.1.30 includes the necessary patch to validate headers and prevent unauthorized access.

References