Impact
This vulnerability allows an attacker to supply an arbitrary URL via the X‑GitLab‑API‑URL header when the ENABLE_DYNAMIC_API_URL environment variable is true. The server validates only that the string is a syntactically correct URL, then forwards all outbound GitLab API requests to that address, automatically attaching the victim's Private‑Token. The attacker can capture the token and use it to perform privileged actions. The weakness is a Server‑Side Request Forgery defined as CWE‑918.
Affected Systems
Affected product: zereight/gitlab‑mcp. All releases from 0.0.1 up to, but not including, 2.1.27 are vulnerable. The patch was released in v2.1.27. Users running any earlier version that has ENABLE_DYNAMIC_API_URL enabled are at risk.
Risk and Exploitability
The CVSS score of 9.6 indicates a high‑severity problem. However, the EPSS score of less than 1% shows that exploitation is currently unobserved or rare. The vulnerability is not listed in the CISA KEV catalog. An attacker must be able to send HTTP requests to the server; once they do, the SSRF can be used to exfiltrate the authentication token or direct the server to internal resources. No user interaction beyond supplying a header is needed, suggesting moderate effort on the attacker side.
OpenCVE Enrichment
Github GHSA