CVE-2026-61560: Three Critical Vulnerabilities in GitLab-MCP

This text was generated using artificial intelligence (AI).For the npm package @zereight/mcp-gitlab three critical vulnerabilities were published on September 15, 2026: CVE-2026-61560, CVE-2026-61568 and CVE-2026-61559. The package provides a Model Context Protocol server for GitLab and can be operated via SSE or Streamable HTTP. The vulnerabilities CVE-2026-61560 and CVE-2026-61559 were discovered by Pluto Security and coordinated publicly disclosed.

The advisories concern unprotected MCP functions, the sharing of GitLab tokens via redirected API calls, and the lack of effective checks on Host- and Originheaders. Upgrading to Version 2.1.30 or higher resolves all three published CVEs.

Are my systems affected? Check now →