CVE-2026-61559

LOW

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

0.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Deep dive

Full discourse2 posts
  • Upwind Security MDR@UpwindMDR

    🚨Critical - @zereight/mcp-gitlab SSRF via X-GitLab-API-URL Token Exfil (CVE-2026-61559) When ENABLE_DYNAMIC_API_URL=true, @zereight/mcp-gitlab trusts the X-GitLab-API-URL request header as the base URL for outbound GitLab API calls with no allowlist/hostname checks. An attacker reaching the HTTP transport can redirect requests to an attacker host and capture the victim GitLab Private-Token. Deployments with ENABLE_DYNAMIC_API_URL=false are not affected. 👉Affected: @zereight/mcp-gitlab >= 0.0.1 and < 2.1.27 | Upgrade to 2.1.27

    31020204
    303 followersView on X
  • CVE@CVEnew

    CVE-2026-61559 `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1.27, when the environment variable `ENABLE_DYN… https://www.cve.org/CVERecord?id=CVE-2026-61559

    00000837
    58.1K followersView on X

Explore more