CVE-2026-61559: @zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery
When the environment variable ENABLE_DYNAMIC_API_URL=true is set, the server
reads the X-GitLab-API-URL HTTP request header and uses it as the base URL for
all outbound GitLab API calls made within that request. The server validates that
the value is a well-formed URL (new URL(dynamicApiUrl)) but applies no
allowlist or hostname restriction. The server then attaches the victim’s
Private-Token to every outbound fetch that uses the redirected URL.
Any caller who can reach the HTTP transport can set X-GitLab-API-URL to an
attacker-controlled host. The next GitLab API call the server makes delivers the
victim’s token to that host.
The vulnerable code appears at two locations.
SSE handler (index.ts:11541):
const dynamicApiUrl = req.headers["x-gitlab-api-url"]?.trim();
if (ENABLE_DYNAMIC_API_URL && dynamicApiUrl) {
apiUrl = normalizeGitLabApiUrl(dynamicApiUrl); // no allowlist check
}
Streamable HTTP handler (index.ts:11787), inside parseAuthHeaders:
const dynamicApiUrl = req.headers["x-gitlab-api-url"]?.trim();
if (ENABLE_DYNAMIC_API_URL && dynamicApiUrl) {
new URL(dynamicApiUrl); // syntax-only check
apiUrl = normalizeGitLabApiUrl(dynamicApiUrl); // any reachable host accepted
}
In both cases, apiUrl propagates through getEffectiveApiUrl() and into
getFetchConfig(), which attaches Private-Token: <victim_token> to every
outbound fetch. The token reaches the attacker’s host, not GitLab.
References
- github.com/advisories/GHSA-2h44-8472-frjj
- github.com/zereight/gitlab-mcp/commit/6ffb4cc70706fd05b1ab80901676bc2998b6db6d
- github.com/zereight/gitlab-mcp/pull/625
- github.com/zereight/gitlab-mcp/releases/tag/v2.1.27
- github.com/zereight/gitlab-mcp/security/advisories/GHSA-2h44-8472-frjj
- nvd.nist.gov/vuln/detail/CVE-2026-61559
Code Behaviors & Features
Detect and mitigate CVE-2026-61559 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →