Impact
The Modèle Context Protocol server for GitLab, when deployed in versions before 2.1.30, does not enforce a Host or Origin allowlist on its Streamable HTTP MCP endpoint. This omission allows a malicious web page to employ DNS rebinding so that browser requests are directed to a victim’s local MCP listener while carrying attacker‑controlled Host and Origin headers. The server accepts these headers and initiates the MCP initialization path instead of rejecting the request at the HTTP boundary, enabling the attacker to execute privileged operations or compromise the local system. This represents a remote code execution flaw (CWE‑350).
Affected Systems
The vulnerability affects the zereight:gitlab-mcp Model Context Protocol server used in GitLab deployments. Any installation running a version earlier than 2.1.30 is susceptible. Once upgraded to 2.1.30 or newer, the patch removes the open Host and Origin validation and mitigates the risk.
Risk and Exploitability
The CVSS base score of 9.6 reflects a critical impact and a high attack complexity. The EPSS score of less than 1% indicates a low current probability of exploitation, but the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires a victim to load a malicious web page that performs DNS rebinding; the attacker must control the DNS resolution for the victim’s local MCP listener. When the request reaches the server, the lack of header validation permits the initiation of local MCP commands, potentially resulting in full remote code execution on the host.
OpenCVE Enrichment
Github GHSA