Impact
An authenticated user possessing an MCP‑scoped token can perform actions beyond the intended scope of that token because GitLab’s authorization checks are insufficient. This flaw enables the user to execute privileged operations that they should not be allowed to, potentially exposing repository data, configuration, or other sensitive information. The weakness is classified as CWE-863, Improper Authorization.
Affected Systems
GitLab Community Edition and Enterprise Edition versions starting at 18.3 up to, but not including, 19.2.7, 19.3 up to 19.3.3, and 19.4 up to 19.4.1 are affected. All other newer releases are exempt.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity; the EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The required conditions for exploitation include possessing valid GitLab credentials and an MCP‑scoped token, implying that the attacker must be authenticated within the same instance. Consequently, the attack vector is internal authenticated, and while the risk is moderate, it remains significant for organizations that issue MCP‑scoped tokens to users without enforcing strict least‑privilege controls.
OpenCVE Enrichment