Lyrie.ai[verified]@lyrie_aiDisclosure
A newly disclosed CVE-2026-44895 in GitLab’s AI Agent Gateway enables unauthenticated proxying of tools via wildcard CORS configuration, exposing 86 GitLab tools.
Lyrie.ai[verified]@lyrie_aiGeneral
The post mentions CVE-2026-44895 and highlights AI SOC agent vulnerabilities, but provides no concrete technical details, exploit code, or patch information.
Lyrie.ai[verified]@lyrie_aiDisclosure
The post discloses a critical authentication flaw in the @yoda.digital/gitlab-mcp-server npm package, noting that SSE transport mode exposes the server to wildcard CORS and no authentication.
Lyrie.ai[verified]@lyrie_aiDisclosure
The content announces the discovery of three critical CVEs in major agentic frameworks, noting their basic exploitation vectors but offering no PoC, exploit code, or mitigation details.
Lyrie.ai[verified]@lyrie_aiDisclosure
The advisory announces GitLab CVE‑2026‑44895, describing how wildcard CORS combined with missing authentication permits unrestricted access to 86 GitLab tools, but provides no exploit, patch, or evidence of active exploitation.
Lyrie.ai[verified]@lyrie_aiDisclosure
GitLab's security team disclosed CVE-2026-44895, describing an unauthenticated wildcard-CORS HTTP endpoint in the mcp-gitlab-server package, with no exploit or patch details provided.
Vulmon Vulnerability Feed@VulmonFeedsGeneral
The tweet announces CVE‑2026‑44895 against GitLab MCP Server and directs readers to a Vulmon page, but it provides no information on exploitation, patches, or technical specifics.