CVE-2026-44895Disclosure

LOWCVSS 9.2 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

GitLab MCP Server lets an AI agent talk directly to GitLab. Prior to 0.6.0, the HTTP transport in src/transport.ts ships with no authentication layer at all and a wildcard Access-Control-Allow-Origin: * on every response. The structural defect is that the SSE server stands up a stateful, mutation-capable RPC endpoint that is backed by the operator's GITLAB_PERSONAL_ACCESS_TOKEN without any inbound credential check, then advertises itself to every cross-origin browser context via the wildcard CORS header. The httpServer.listen(port) call at line 97 also passes no host argument, so the bind defaults to 0.0.0.0 and exposes the auth-less surface on every interface. This vulnerability is fixed in 0.6.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306CWE-942

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 4 mentions (2026-06-17); latest day: 1
  • 7 total mentions across 4 days

Deep dive

Activity timeline7 mentions / 4d
01234Mentions · 2026-05-27: 1Mentions · 2026-06-17: 4Mentions · 2026-06-19: 1Mentions · 2026-06-24: 1Technical Details · 2026-06-17: 4Technical Details · 2026-06-19: 105-2706-1706-1906-24
Signal classification2 categories
Disclosure
571.4%
General
228.6%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-271
General1
2026-06-174
Disclosure4
2026-06-191
Disclosure1
2026-06-241
General1
Full discourse7 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    The AI Agent Gateway: CVE-2026-44895 Turns GitLab MCP Server into an Unauthenticated Tool Proxy. The AI Agent Gateway Bypass: How Wildcard CORS + No Auth = Unguarded Access to 86 GitLab Tools

    Post summary

    A newly disclosed CVE-2026-44895 in GitLab’s AI Agent Gateway enables unauthenticated proxying of tools via wildcard CORS configuration, exposing 86 GitLab tools.

    40020328
    324 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    1. Agentic agent security itself. Every AI SOC agent has an attack surface. Prompt injection, context poisoning, and MCP server vulnerabilities (see CVE-2026-44895 from earlier today) represent novel ways to neutralize a defender's own AI infrastructure. Governance…

    Post summary

    The post mentions CVE-2026-44895 and highlights AI SOC agent vulnerabilities, but provides no concrete technical details, exploit code, or patch information.

    2000051
    295 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-44895 exposes a catastrophic authentication gap in the @yoda.digital/gitlab-mcp-server npm package: when SSE transport is enabled (the README's recommended mode), the HTTP server runs with wildcard CORS and zero authentication checks. An attacker on the same…

    Post summary

    The post discloses a critical authentication flaw in the @yoda.digital/gitlab-mcp-server npm package, noting that SSE transport mode exposes the server to wildcard CORS and no authentication.

    1001053
    289 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    In the last 72 hours, researchers have disclosed critical vulnerabilities in three major agentic frameworks: CVE-2026-25592 & CVE-2026-26030 (Semantic Kernel): Prompt injection RCE CVE-2026-42302 (FastGPT): Agent runtime sandbox escape CVE-2026-44895 (GitLab MCP Server):…

    Post summary

    The content announces the discovery of three critical CVEs in major agentic frameworks, noting their basic exploitation vectors but offering no PoC, exploit code, or mitigation details.

    1000050
    294 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    @yoda Sources GitLab Advisories: CVE-2026-44895 GitHub Advisory Database: GHSA-8jr5-6gvj-rfpf NVD: CVE-2026-44895 mcp-gitlab-server Repository The AI Agent Gateway Bypass: How Wildcard CORS + No Auth = Unguarded Access to 86 GitLab Tools

    Post summary

    The advisory announces GitLab CVE‑2026‑44895, describing how wildcard CORS combined with missing authentication permits unrestricted access to 86 GitLab tools, but provides no exploit, patch, or evidence of active exploitation.

    1000083
    289 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    @yoda On May 9, 2026, GitLab's security team disclosed CVE-2026-44895: the mcp-gitlab-server package (used to expose GitLab as an MCP—Model Context Protocol—interface for AI agents and automation tools) ships with an unauthenticated, wildcard-CORS HTTP endpoint when the…

    Post summary

    GitLab's security team disclosed CVE-2026-44895, describing an unauthenticated wildcard-CORS HTTP endpoint in the mcp-gitlab-server package, with no exploit or patch details provided.

    1000060
    289 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-44895 GitLab MCP Server lets an AI agent talk directly to GitLab. Prior... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-44895 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The tweet announces CVE‑2026‑44895 against GitLab MCP Server and directs readers to a Vulmon page, but it provides no information on exploitation, patches, or technical specifics.

    0000074
    4.0K followersView on X

Explore more