Description
`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expose the Streamable HTTP MCP endpoint without an effective Host or Origin allowlist. A malicious web page can use DNS rebinding to route browser requests to a victim's local MCP listener while preserving an attacker-controlled `Host` and `Origin`. The server accepts those headers and reaches the MCP initialization path instead of rejecting the request at the HTTP boundary. Version 2.1.30 contains a patch.
Published: 2026-09-15
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

The Modèle Context Protocol server for GitLab, when deployed in versions before 2.1.30, does not enforce a Host or Origin allowlist on its Streamable HTTP MCP endpoint. This omission allows a malicious web page to employ DNS rebinding so that browser requests are directed to a victim’s local MCP listener while carrying attacker‑controlled Host and Origin headers. The server accepts these headers and initiates the MCP initialization path instead of rejecting the request at the HTTP boundary, enabling the attacker to execute privileged operations or compromise the local system. This represents a remote code execution flaw (CWE‑350).

Affected Systems

The vulnerability affects the zereight:gitlab-mcp Model Context Protocol server used in GitLab deployments. Any installation running a version earlier than 2.1.30 is susceptible. Once upgraded to 2.1.30 or newer, the patch removes the open Host and Origin validation and mitigates the risk.

Risk and Exploitability

The CVSS base score of 9.6 reflects a critical impact and a high attack complexity. The EPSS score of less than 1% indicates a low current probability of exploitation, but the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires a victim to load a malicious web page that performs DNS rebinding; the attacker must control the DNS resolution for the victim’s local MCP listener. When the request reaches the server, the lack of header validation permits the initiation of local MCP commands, potentially resulting in full remote code execution on the host.

Generated by OpenCVE AI on September 18, 2026 at 13:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the zereight:gitlab-mcp software to version 2.1.30 or later, which includes a patch that enforces Host and Origin validation on the Streamable HTTP MCP endpoint.
  • If the service is exposed to the internet, restrict its inbound traffic to trusted networks only, using firewall rules or access controls, to reduce the attack surface.
  • After updating, verify that no local services can be reached via DNS rebinding and apply network segmentation as a preventive measure.

Generated by OpenCVE AI on September 18, 2026 at 13:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-vmp7-252j-cwp7 @zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Zereight
Zereight gitlab-mcp
Vendors & Products Zereight
Zereight gitlab-mcp

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Description `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expose the Streamable HTTP MCP endpoint without an effective Host or Origin allowlist. A malicious web page can use DNS rebinding to route browser requests to a victim's local MCP listener while preserving an attacker-controlled `Host` and `Origin`. The server accepts those headers and reaches the MCP initialization path instead of rejecting the request at the HTTP boundary. Version 2.1.30 contains a patch.
Title @zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport
Weaknesses CWE-350
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Zereight Gitlab-mcp
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T18:36:39.016Z

Reserved: 2026-07-10T16:48:39.924Z

Link: CVE-2026-61568

cve-icon Vulnrichment

Updated: 2026-09-16T18:23:18.172Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T21:16:41.570

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-61568

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T14:00:10Z

Weaknesses
  • CWE-350

    Reliance on Reverse DNS Resolution for a Security-Critical Action