{"id":99153,"date":"2026-09-16T01:22:04","date_gmt":"2026-09-15T23:22:04","guid":{"rendered":"https:\/\/locaterisk.com\/de\/?p=99153"},"modified":"2026-09-16T01:22:04","modified_gmt":"2026-09-15T23:22:04","slug":"zereight-mcp-gitlab-cve-2026-61560","status":"publish","type":"post","link":"https:\/\/locaterisk.com\/fr\/zereight-mcp-gitlab-cve-2026-61560\/","title":{"rendered":"CVE-2026-61560 : Trois vuln\u00e9rabilit\u00e9s critiques dans GitLab-MCP"},"content":{"rendered":"\n<div class=\"wp-block-lr-blog-article-header-module\">\n    <div class=\"content\">\n\t\t<div class=\"headline\">\n\t\t\t<a class=\"to-blog-button\" href=\"https:\/\/locaterisk.com\/fr\/blog\/\">\n\t\t\t\t<span class=\"to-blog-arrow\" aria-hidden=\"true\">\u2190<\/span>\n\t\t\t\t<span>Retour au blog<\/span>\n\t\t\t<\/a>\n\t\t\t<div class=\"article-meta\">\n\t\t\t\t\t\t\t\t\t<p class=\"post-updated\">Publi\u00e9: 16 septembre 2026<\/p>\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t<\/div>\n        <div class=\"main-content\">\n\t\t\t<h1 class=\"title\">CVE-2026-61560: Drei kritische Schwachstellen in GitLab-MCP<\/h1>\n\t\t\t\t\t\t\t<p class=\"paragraph\"><span class=\"lr-ai-disclosure\" style=\"display:block;margin:8px 0 28px;font-size:14px;line-height:1.4;color:#8b93a7;font-family:inherit;font-style:italic\">Dieser Text wurde mit k\u00fcnstlicher Intelligenz (KI) erstellt.<\/span>F\u00fcr das npm-Paket <strong>@zereight\/mcp-gitlab<\/strong> wurden am 15. September 2026 drei kritische Schwachstellen ver\u00f6ffentlicht: <strong>CVE-2026-61560<\/strong>, <strong>CVE-2026-61568<\/strong> und <strong>CVE-2026-61559<\/strong>. Das Paket stellt einen Model-Context-Protocol-Server f\u00fcr GitLab bereit und kann \u00fcber SSE oder Streamable HTTP betrieben werden. Die Schwachstellen CVE-2026-61560 und CVE-2026-61559 wurden von Pluto Security entdeckt und koordiniert offengelegt.<br><br>Die Advisories betreffen ungesch\u00fctzte MCP-Funktionen, die Weitergabe von GitLab-Tokens \u00fcber umgeleitete API-Aufrufe sowie fehlende wirksame Pr\u00fcfungen von <strong>Host<\/strong>&#8211; und <strong>Origin<\/strong>-Headern. Ein Upgrade auf <strong>Version 2.1.30 oder h\u00f6her<\/strong> behebt alle drei ver\u00f6ffentlichten CVEs.<br><br><a href=\"#cve-check\" class=\"lr-cveqc-jump\" style=\"display:inline-block;font-weight:700;color:#26d9c3;text-decoration:none\">Sind meine Systeme betroffen? Jetzt pr\u00fcfen \u2192<\/a><\/p>\n\t\t\t        <\/div>\n    <\/div>\n<\/div>\n\n\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"400\" height=\"400\" src=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/vulnerability-disclosure.png\" alt=\"CVE-2026-61560: Drei kritische Schwachstellen in GitLab-MCP\" class=\"wp-image-9138\" srcset=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/vulnerability-disclosure.png 400w, https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/vulnerability-disclosure-300x300.png 300w, https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/vulnerability-disclosure-150x150.png 150w, https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/vulnerability-disclosure-12x12.png 12w\" sizes=\"auto, (max-width: 400px) 100vw, 400px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\"><strong>Auf einen Blick:<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>Produkt \/ Komponente<\/th><th>Betroffene Versionen<\/th><th>Gepatcht in<\/th><\/tr><\/thead><tbody><tr><td>@zereight\/mcp-gitlab<\/td><td>[object Object], [object Object]<\/td><td>2.1.27, 2.1.30<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Schwachstelle: <strong>CVE-2026-61560<\/strong> (<strong>CVSS 9.8<\/strong>, kritisch); weitere: <strong>CVE-2026-61568<\/strong>, <strong>CVE-2026-61559<\/strong><\/li>\n\n\n\n<li>Status: kein aktiver Missbrauch belegt<\/li>\n\n\n\n<li>Patch verf\u00fcgbar seit: 15.09.2026<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>CVE-2026-61560: Unauthentifizierter SSE-Transport und Dateizugriff<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Laut dem GitHub Security Advisory zu CVE-2026-61560 (GHSA-cv3r-c5h8-f4g5) betrifft die Schwachstelle (<strong>CVSS 9.8<\/strong>, CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H) Versionen vor <strong>2.1.27<\/strong>. Im SSE-Modus mit <strong>SSE=true<\/strong> waren alle MCP-Werkzeuge ohne Authentifizierung erreichbar.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Zus\u00e4tzlich verarbeitet das Werkzeug <strong>upload_markdown<\/strong> einen unzureichend bereinigten Parameter <strong>file_path<\/strong>. Dadurch konnte das Werkzeug beliebige lokale Dateien vom Dateisystem des Servers lesen und in ein GitLab-Projekt hochladen. Das Advisory nennt <strong>\/proc\/self\/environ<\/strong> als m\u00f6glichen Zielpfad.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Befindet sich dort ein <strong>GITLAB_PERSONAL_ACCESS_TOKEN<\/strong>, kann ein nicht authentifizierter, \u00fcber das Netzwerk erreichbarer Angreifer den Token auslesen. Das Advisory beschreibt als m\u00f6gliche Folge die \u00dcbernahme des zugeh\u00f6rigen GitLab-Kontos.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">F\u00fcr Docker-Deployments ist dieser Befund besonders relevant: Der SSE-Modus ist dort laut Advisory standardm\u00e4\u00dfig aktiviert. Version <strong>2.1.27<\/strong> enth\u00e4lt einen Patch f\u00fcr CVE-2026-61560.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>CVE-2026-61559: Token-Abfluss \u00fcber dynamische API-Ziele<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>CVE-2026-61559<\/strong> (GHSA-2h44-8472-frjj) erreicht einen <strong>CVSS-Score von 9.6<\/strong> (CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:H\/I:H\/A:N) und betrifft Versionen ab <strong>0.0.1<\/strong> und vor <strong>2.1.27<\/strong>, wenn <strong>ENABLE_DYNAMIC_API_URL=true<\/strong> gesetzt ist. Der Server \u00fcbernimmt in dieser Konfiguration den HTTP-Header <strong>X-GitLab-API-URL<\/strong> als Basisadresse f\u00fcr GitLab-API-Aufrufe innerhalb der jeweiligen Anfrage.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Die Adresse wird auf ein g\u00fcltiges URL-Format gepr\u00fcft, jedoch ohne Allowlist oder Einschr\u00e4nkung auf bestimmte Hostnamen. Der Server f\u00fcgt seinen <strong>Private-Token<\/strong> den ausgehenden API-Anfragen hinzu. Ein Aufrufer mit Zugang zum HTTP-Transport kann dadurch eine kontrollierte Zieladresse \u00fcbergeben; bei einem folgenden GitLab-API-Aufruf kann der Token an diese Adresse \u00fcbertragen werden.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Version <strong>2.1.27<\/strong> enth\u00e4lt einen Patch f\u00fcr CVE-2026-61559. Bis das Update eingespielt ist, sollte <strong>ENABLE_DYNAMIC_API_URL=true<\/strong> deaktiviert bleiben, sofern die Funktion nicht ben\u00f6tigt wird.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>CVE-2026-61568: DNS-Rebinding gegen lokale MCP-Listener<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>CVE-2026-61568<\/strong> (GHSA-vmp7-252j-cwp7) erreicht einen <strong>CVSS-Score von 9.6<\/strong> (CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:H\/I:H\/A:H) und betrifft Versionen vor <strong>2.1.30<\/strong>. Die Schwachstelle liegt im Streamable-HTTP-Transport. Laut dem GitHub Security Advisory fehlte eine wirksame Allowlist f\u00fcr <strong>Host<\/strong>&#8211; und <strong>Origin<\/strong>-Header.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Eine b\u00f6sartige Webseite kann bei einem DNS-Rebinding-Angriff Browser-Anfragen an einen lokalen MCP-Listener des Opfers leiten und dabei angreiferkontrollierte <strong>Host<\/strong>&#8211; und <strong>Origin<\/strong>-Werte beibehalten. Der betroffene Server akzeptierte diese Header und erreichte den MCP-Initialisierungspfad.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Dieser Angriffspfad betrifft insbesondere lokal erreichbare MCP-Dienste. Version <strong>2.1.30<\/strong> enth\u00e4lt einen Patch f\u00fcr CVE-2026-61568.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Ma\u00dfnahmen f\u00fcr betroffene Deployments<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Die bereitgestellten Empfehlungen konzentrieren sich auf Patch-Management, Zugriffsbeschr\u00e4nkung und den Schutz verwendeter GitLab-Tokens:<\/p>\n\n\n\n<ol class=\"wp-block-list has-text-color\" style=\"color:#ffffff\">\n<li><strong><strong>@zereight\/mcp-gitlab<\/strong> auf Version 2.1.30 oder h\u00f6her aktualisieren.<\/strong> Diese Version adressiert alle drei ver\u00f6ffentlichten CVEs.<\/li>\n\n\n\n<li><strong>SSE deaktivieren oder absichern<\/strong>, wenn ein Upgrade noch nicht erfolgt ist.<\/li>\n\n\n\n<li><strong><strong>ENABLE_DYNAMIC_API_URL=true<\/strong> deaktivieren<\/strong>, sofern diese Konfiguration nicht zwingend erforderlich ist.<\/li>\n\n\n\n<li><strong><strong>GITLAB_PERSONAL_ACCESS_TOKEN<\/strong> rotieren<\/strong>, wenn der Dienst ohne Authentifizierung erreichbar war.<\/li>\n\n\n\n<li><strong>Netzwerkzugriffe auf vertrauensw\u00fcrdige Clients begrenzen<\/strong>, etwa \u00fcber Firewall-Regeln oder eine lokale Bindung des Dienstes.<\/li>\n\n\n\n<li><strong>Docker-Deployments priorisiert pr\u00fcfen und patchen<\/strong>, da der SSE-Modus dort als Standardkonfiguration aktiviert ist.<\/li>\n\n\n\n<li><strong>MCP-Server hinter einer Authentifizierungsschicht betreiben.<\/strong><\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Die Patch-Pr\u00fcfung sollte technische Betriebsparameter einbeziehen: aktiver Transportmodus, Netzwerkerreichbarkeit, gesetzte Umgebungsvariablen und verwendete GitLab-Tokens. Die installierte Paketversion allein zeigt nicht, ob ein Dienst per SSE erreichbar ist oder ob <strong>ENABLE_DYNAMIC_API_URL=true<\/strong> aktiv gesetzt wurde.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Organisationen in Deutschland und \u00d6sterreich, die MCP-basierte CI\/CD-Dienste im Rahmen von NIS-2-pflichtigen Prozessen betreiben, sollten pr\u00fcfen, ob ein kompromittierter GitLab-Token als sicherheitsrelevanter Vorfall meldepflichtig ist. Nach Art. 33 DSGVO besteht bei einer Verletzung des Schutzes personenbezogener Daten eine 72-Stunden-Meldepflicht gegen\u00fcber der zust\u00e4ndigen Aufsichtsbeh\u00f6rde. F\u00fcr Betreiber in der Schweiz gilt das revidierte Informationssicherheitsgesetz (ISG); meldepflichtige Vorf\u00e4lle sind dort an das Bundesamt f\u00fcr Cybersicherheit (BACS) zu richten.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Sichtbarkeit f\u00fcr exponierte MCP-Dienste<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Der Fall ist f\u00fcr External Attack Surface Management relevant, weil <strong>@zereight\/mcp-gitlab<\/strong> als HTTP-Dienst mit SSE- und Streamable-HTTP-Transport betrieben werden kann. Solche Dienste k\u00f6nnen unter Unternehmensdomains oder in zugeh\u00f6rigen IT-Umgebungen erreichbar sein \u2014 auch dann, wenn sie nicht zentral inventarisiert wurden.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">LocateRisk kann im EASM-Kontext die Sicht auf extern erreichbare Dienste, unerwartete HTTP-Endpunkte und verwaiste CI-Infrastruktur unterst\u00fctzen. Diese Sichtbarkeit ersetzt keine Pr\u00fcfung der konkreten Paketversion, der aktiven Transportkonfiguration oder der Berechtigungen eines GitLab-Tokens.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Erg\u00e4nzend unterst\u00fctzt LocateRisks Cyber Vendor Risk Management dabei, das Sicherheitsniveau von Drittanbietern kontinuierlich zu beobachten und sicherheitsrelevante Ver\u00e4nderungen fr\u00fchzeitig zu erkennen. Bei npm-Abh\u00e4ngigkeiten und betriebenen MCP-Diensten lassen sich damit technische Erreichbarkeit und Abh\u00e4ngigkeitsrisiken in getrennten Pr\u00fcfpfaden betrachten.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Bin ich betroffen?<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Betroffen ist @zereight\/mcp-gitlab in den oben genannten Versionen; behoben wurde die Schwachstelle in 2.1.27, 2.1.30. Wer wissen will, ob @zereight\/mcp-gitlab in der eigenen extern erreichbaren Infrastruktur \u00fcberhaupt sichtbar ist, kann den <a href=\"#cve-check\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-Quick-Check<\/a> am Ende dieses Artikels nutzen: Er zeigt exponierte Systeme und die von au\u00dfen erkennbare Software.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Die konkret installierte Version l\u00e4sst sich von au\u00dfen nicht in jedem Fall bestimmen \u2014 ausschlaggebend ist der Abgleich mit dem Hersteller-Advisory.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Quellen und weitere Infos<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>GitHub Advisory Database \/ zereight:<\/strong> <a href=\"https:\/\/github.com\/zereight\/gitlab-mcp\/security\/advisories\/GHSA-cv3r-c5h8-f4g5\" target=\"_blank\" rel=\"noreferrer noopener\">GHSA-cv3r-c5h8-f4g5 \/ CVE-2026-61560<\/a><\/li>\n\n\n\n<li><strong>GitHub Advisory Database \/ zereight:<\/strong> <a href=\"https:\/\/github.com\/zereight\/gitlab-mcp\/security\/advisories\/GHSA-vmp7-252j-cwp7\" target=\"_blank\" rel=\"noreferrer noopener\">GHSA-vmp7-252j-cwp7 \/ CVE-2026-61568<\/a><\/li>\n\n\n\n<li><strong>GitHub Advisory Database \/ zereight:<\/strong> <a href=\"https:\/\/github.com\/zereight\/gitlab-mcp\/security\/advisories\/GHSA-2h44-8472-frjj\" target=\"_blank\" rel=\"noreferrer noopener\">GHSA-2h44-8472-frjj \/ CVE-2026-61559<\/a><\/li>\n\n\n\n<li><strong>zereight \/ GitHub Releases:<\/strong> <a href=\"https:\/\/github.com\/zereight\/gitlab-mcp\/releases\/tag\/v2.1.27\" target=\"_blank\" rel=\"noreferrer noopener\">Release v2.1.27<\/a><\/li>\n\n\n\n<li><strong>zereight \/ GitHub Releases:<\/strong> <a href=\"https:\/\/github.com\/zereight\/gitlab-mcp\/releases\/tag\/v2.1.30\" target=\"_blank\" rel=\"noreferrer noopener\">Release v2.1.30<\/a><\/li>\n\n\n\n<li><strong>Pluto Security:<\/strong> <a href=\"https:\/\/pluto.security\/blog\/two-critical-vulnerabilities-gitlab-mcp-account-takeover\/\" target=\"_blank\" rel=\"noreferrer noopener\">One Request to Own Every Repo: How We Hijacked GitLab Through Its MCP Server<\/a><\/li>\n<\/ul>\n\n\n\n<div class=\"wp-block-lr-faq-module\"><div class=\"content\"><h3><strong>H\u00e4ufige Fragen<\/strong><\/h3><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\"><strong>Was ist @zereight\/mcp-gitlab?<\/strong><\/a><img class=\"collapse-toggle\" srcset=\"https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\"><strong>@zereight\/mcp-gitlab<\/strong> ist ein npm-Paket, das einen Model-Context-Protocol-Server (MCP) f\u00fcr GitLab bereitstellt. Es erm\u00f6glicht die Interaktion mit GitLab-Projekten \u00fcber SSE- oder Streamable-HTTP-Transport und wird unter anderem in Docker-Umgebungen eingesetzt, wo der SSE-Modus standardm\u00e4\u00dfig aktiviert ist.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\"><strong>Welche Versionen sind betroffen und wie patche ich?<\/strong><\/a><img class=\"collapse-toggle\" srcset=\"https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">CVE-2026-61560 und CVE-2026-61559 betreffen alle Versionen vor 2.1.27; CVE-2026-61568 betrifft alle Versionen vor 2.1.30. Ein Upgrade auf Version <strong>2.1.30 oder h\u00f6her<\/strong> behebt alle drei Schwachstellen in einem Schritt. Bis das Update eingespielt ist, sollten SSE und <strong>ENABLE_DYNAMIC_API_URL=true<\/strong> deaktiviert sowie verwendete <strong>GITLAB_PERSONAL_ACCESS_TOKEN<\/strong>-Werte rotiert werden.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\"><strong>Bin ich gef\u00e4hrdet, wenn ich SSE nicht aktiv nutze?<\/strong><\/a><img class=\"collapse-toggle\" srcset=\"https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">CVE-2026-61568 (DNS-Rebinding) betrifft den Streamable-HTTP-Transport und ist unabh\u00e4ngig vom SSE-Modus. CVE-2026-61559 greift, wenn <strong>ENABLE_DYNAMIC_API_URL=true<\/strong> gesetzt ist. Ein Deployment ist daher auch ohne aktiviertes SSE potenziell angreifbar, sofern eine der anderen Konfigurationen vorliegt und die jeweilige Version nicht gepatcht ist.<\/p><\/div><\/div><\/div><\/div>\n\n\n\n<script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@type\":\"FAQPage\",\"@id\":\"https:\/\/locaterisk.com\/de\/zereight-mcp-gitlab-cve-2026-61560\/#faq\",\"url\":\"https:\/\/locaterisk.com\/de\/zereight-mcp-gitlab-cve-2026-61560\/\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/locaterisk.com\/de\/zereight-mcp-gitlab-cve-2026-61560\/\"},\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"Was ist @zereight\/mcp-gitlab?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"@zereight\/mcp-gitlab ist ein npm-Paket, das einen Model-Context-Protocol-Server (MCP) f\u00fcr GitLab bereitstellt. Es erm\u00f6glicht die Interaktion mit GitLab-Projekten \u00fcber SSE- oder Streamable-HTTP-Transport und wird unter anderem in Docker-Umgebungen eingesetzt, wo der SSE-Modus standardm\u00e4\u00dfig aktiviert ist.\"}},{\"@type\":\"Question\",\"name\":\"Welche Versionen sind betroffen und wie patche ich?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"CVE-2026-61560 und CVE-2026-61559 betreffen alle Versionen vor 2.1.27; CVE-2026-61568 betrifft alle Versionen vor 2.1.30. Ein Upgrade auf Version 2.1.30 oder h\u00f6her behebt alle drei Schwachstellen in einem Schritt. Bis das Update eingespielt ist, sollten SSE und ENABLE_DYNAMIC_API_URL=true deaktiviert sowie verwendete GITLAB_PERSONAL_ACCESS_TOKEN-Werte rotiert werden.\"}},{\"@type\":\"Question\",\"name\":\"Bin ich gef\u00e4hrdet, wenn ich SSE nicht aktiv nutze?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"CVE-2026-61568 (DNS-Rebinding) betrifft den Streamable-HTTP-Transport und ist unabh\u00e4ngig vom SSE-Modus. CVE-2026-61559 greift, wenn ENABLE_DYNAMIC_API_URL=true gesetzt ist. Ein Deployment ist daher auch ohne aktiviertes SSE potenziell angreifbar, sofern eine der anderen Konfigurationen vorliegt und die jeweilige Version nicht gepatcht ist.\"}}]}<\/script>\n\n\n<p class=\"lr-legal-note\" style=\"margin:32px 0 0;padding-top:16px;border-top:1px solid #e5e7eb;font-size:13px;line-height:1.55;color:#8b93a7;font-style:italic;\">Stand: 16.09.2026. Dieser Beitrag dient allgemeinen Informationszwecken und ist keine Rechts-, Sicherheits- oder Handlungsberatung im Einzelfall. Sicherheitslage und Patch-Verf\u00fcgbarkeit k\u00f6nnen sich seit der Ver\u00f6ffentlichung ge\u00e4ndert haben; ma\u00dfgeblich ist stets das verlinkte Hersteller-Advisory. Trotz sorgf\u00e4ltiger Recherche \u00fcbernehmen wir keine Gew\u00e4hr f\u00fcr Aktualit\u00e4t, Richtigkeit und Vollst\u00e4ndigkeit.<\/p>\n\n\n<div id=\"cve-check\" style=\"scroll-margin-top:100px\"><\/div>\n\n\n\n\t<div class=\"wp-block-lr-cve-quick-check lr-cveqc\">\n\t\t<div class=\"lr-cveqc-inner\">\n\n\t\t\t<div class=\"lr-cveqc-story\">\n\t\t\t\t<h2 class=\"lr-cveqc-headline\">CVE Quick Check<\/h2>\n\t\t\t\t<p class=\"lr-cveqc-text\">Pr\u00fcfen Sie in wenigen Minuten, ob zu einer aktuellen CVE Hinweise auf Ihrer extern sichtbaren Angriffsfl\u00e4che erkennbar sind.<\/p>\n\n\t\t\t\t<ul class=\"lr-cveqc-bullets\">\n\t\t\t\t\t<li><svg viewBox=\"0 0 26 26\" fill=\"none\" aria-hidden=\"true\"><circle cx=\"13\" cy=\"13\" r=\"12\" stroke=\"#00051d\" stroke-width=\"1.6\"\/><path d=\"M7.5 13.4l3.7 3.6L18.5 9\" stroke=\"#00051d\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/><\/svg><span>Grobe Einsch\u00e4tzung in wenigen Minuten per E-Mail.<\/span><\/li>\t\t\t\t\t<li><svg viewBox=\"0 0 26 26\" fill=\"none\" aria-hidden=\"true\"><circle cx=\"13\" cy=\"13\" r=\"12\" stroke=\"#00051d\" stroke-width=\"1.6\"\/><path d=\"M7.5 13.4l3.7 3.6L18.5 9\" stroke=\"#00051d\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/><\/svg><span>Details im kostenlosen Gespr\u00e4ch mit einem LocateRisk Consultant.<\/span><\/li>\t\t\t\t<\/ul>\n\n\t\t\t\t\t\t\t\t<div class=\"lr-cveqc-teaser\" aria-hidden=\"true\">\n\t\t\t\t\t<h4>Das erhalten Sie per E-Mail<\/h4>\n\t\t\t\t\t<div class=\"lr-cveqc-trow\"><span class=\"k\">Unternehmen<\/span><span class=\"v\">Ihre Firma GmbH<\/span><\/div>\n\t\t\t\t\t\t\t\t\t\t<div class=\"lr-cveqc-trow\"><span class=\"k\">Gepr\u00fcfte CVE<\/span><span class=\"v\">CVE-2026-61560<\/span><\/div>\n\t\t\t\t\t<div class=\"lr-cveqc-trow\"><span class=\"k\">Passive Bewertung<\/span><span class=\"lr-cveqc-lamp\"><i class=\"r\"><\/i><i class=\"y\"><\/i><i class=\"g\"><\/i><\/span><\/div>\t\t\t\t\t<div class=\"lr-cveqc-trow\"><span class=\"k\">Hinweise zur CVE<\/span><span class=\"lr-cveqc-pill\">gefunden oder nicht gefunden<\/span><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<\/div>\n\n\t\t\t<div class=\"lr-cveqc-form-col\">\n\t\t\t\t<form id=\"lr-cveqc-1\" class=\"lr-cveqc-form\" method=\"post\" novalidate\n\t\t\t\t\tdata-ajax-url=\"https:\/\/locaterisk.com\/wp-admin\/admin-ajax.php\">\n\n\t\t\t\t\t<input type=\"text\" name=\"cveId\" required maxlength=\"40\"\n\t\t\t\t\t\tpattern=\"^[Cc][Vv][Ee]-\\d{4}-\\d{4,7}$\"\n\t\t\t\t\t\tvalue=\"CVE-2026-61560\"\n\t\t\t\t\t\tplaceholder=\"CVE-ID, z. B. CVE-2024-3094\" \/>\n\n\t\t\t\t\t<input type=\"email\" name=\"email\" required maxlength=\"320\"\n\t\t\t\t\t\tplaceholder=\"Gesch\u00e4ftliche E-Mail-Adresse\" \/>\n\t\t\t\t\t<p class=\"lr-cveqc-hint\">Bitte verwenden Sie Ihre gesch\u00e4ftliche E-Mail-Adresse. Die Pr\u00fcfung bezieht sich auf das Unternehmen hinter Ihrer E-Mail-Domain; Free-Mail-Adressen (z. B. Gmail) k\u00f6nnen keinem Unternehmen zugeordnet werden.<\/p>\n\n\t\t\t\t\t<!-- Optionale Telefonnummer: nur wer sie angibt, willigt laut Consent-Text\n\t\t\t\t\t     auch in eine telefonische Rueckmeldung ein. autocomplete=\"tel\" ist\n\t\t\t\t\t     gewollt (echtes Feld, kein Honeypot). -->\n\t\t\t\t\t<input type=\"tel\" name=\"phone\" maxlength=\"64\" autocomplete=\"tel\"\n\t\t\t\t\t\tplaceholder=\"Telefon (optional)\" \/>\n\t\t\t\t\t<p class=\"lr-cveqc-hint\">Nur n\u00f6tig, wenn Sie eine kurze telefonische Einordnung m\u00f6chten.<\/p>\n\n\t\t\t\t\t<!-- Honeypot: f\u00fcr Menschen unsichtbar, Bots f\u00fcllen es aus.\n\t\t\t\t\t     Neutraler Feldname (NICHT \"website\"\/\"url\"\/\"email\"), sonst f\u00fcllen\n\t\t\t\t\t     Passwort-Manager und Browser-Autofill das Feld beim echten Nutzer\n\t\t\t\t\t     und blocken ihn faelschlich. -->\n\t\t\t\t\t<div class=\"lr-cveqc-hp\" aria-hidden=\"true\">\n\t\t\t\t\t\t<label>Dieses Feld bitte leer lassen\n\t\t\t\t\t\t\t<input type=\"text\" name=\"lr_hp_check\" tabindex=\"-1\" autocomplete=\"off\" \/>\n\t\t\t\t\t\t<\/label>\n\t\t\t\t\t<\/div>\n\n\t\t\t\t\t<label class=\"lr-cveqc-check\">\n\t\t\t\t\t\t<input type=\"checkbox\" name=\"consentProcessingAccepted\" value=\"1\" required \/>\n\t\t\t\t\t\t<span>Ich stimme zu, dass LocateRisk meine Angaben f\u00fcr den Quick Check verarbeitet, mir das Ergebnis per E-Mail schickt und sich dazu per E-Mail bei mir meldet. Es gelten die <a href=\"\/files\/agb.pdf\" target=\"_blank\" rel=\"noopener\">AGB<\/a> und die <a href=\"\/datenschutz\/\" target=\"_blank\" rel=\"noopener\">Datenschutzerkl\u00e4rung<\/a>.<\/span>\n\t\t\t\t\t<\/label>\n\n\t\t\t\t\t<label class=\"lr-cveqc-check\">\n\t\t\t\t\t\t<input type=\"checkbox\" name=\"cveNotifyOptIn\" value=\"1\" \/>\n\t\t\t\t\t\t<span>Benachrichtigt mich, wenn f\u00fcr extern erkennbare Software neue kritische Schwachstellen (CVSS ab 9) ver\u00f6ffentlicht werden. Jederzeit abbestellbar. (optional)<\/span>\n\t\t\t\t\t<\/label>\n\n\t\t\t\t\t<label class=\"lr-cveqc-check\">\n\t\t\t\t\t\t<input type=\"checkbox\" name=\"marketingOptIn\" value=\"1\" \/>\n\t\t\t\t\t\t<span>Infos zu LocateRisk Produkten und Security-Themen per E-Mail. Jederzeit widerrufbar. (optional)<\/span>\n\t\t\t\t\t<\/label>\n\n\t\t\t\t\t\t\t\t\t\t<input type=\"hidden\" name=\"consentTextVerbatim\" value=\"Ich stimme zu, dass LocateRisk meine Angaben f\u00fcr den Quick Check verarbeitet, mir das Ergebnis per E-Mail schickt und sich dazu per E-Mail bei mir meldet. Es gelten die AGB und die Datenschutzerkl\u00e4rung.\" \/>\n\t\t\t\t\t<input type=\"hidden\" name=\"consentTextVersion\" value=\"qc_consent_fd4a0945\" \/>\n\t\t\t\t\t<input type=\"hidden\" name=\"marketingTextVerbatim\" value=\"Infos zu LocateRisk Produkten und Security-Themen per E-Mail. Jederzeit widerrufbar. (optional)\" \/>\n\t\t\t\t\t<input type=\"hidden\" name=\"marketingTextVersion\" value=\"qc_marketing_cee62603\" \/>\n\t\t\t\t\t<input type=\"hidden\" name=\"locale\" value=\"fr\" \/>\n\t\t\t\t\t<input type=\"hidden\" name=\"blogPostUrl\" value=\"https:\/\/locaterisk.com\/fr\/zereight-mcp-gitlab-cve-2026-61560\/\" \/>\n\t\t\t\t\t<input type=\"hidden\" name=\"utmSource\" value=\"\" \/>\n\t\t\t\t\t<input type=\"hidden\" name=\"utmCampaign\" value=\"\" \/>\n\t\t\t\t\t<input type=\"hidden\" name=\"invalidCveMessage\" value=\"Bitte geben Sie eine g\u00fcltige CVE-ID an (z. B. CVE-2024-3094).\" \/>\n\t\t\t\t\t<input type=\"hidden\" name=\"consentRequiredMessage\" value=\"Bitte stimmen Sie der Verarbeitung zu, damit wir den Quick Check durchf\u00fchren k\u00f6nnen.\" \/>\n\t\t\t\t\t<input type=\"hidden\" name=\"captchaMessage\" value=\"Bitte best\u00e4tigen Sie das reCAPTCHA und versuchen Sie es erneut.\" \/>\n\t\t\t\t\t<input type=\"hidden\" name=\"successMessage\" value=\"Vielen Dank! Bitte best\u00e4tigen Sie Ihre E-Mail-Adresse \u00fcber den Link, den wir Ihnen soeben geschickt haben. Danach starten wir den Quick Check.\" \/>\n\t\t\t\t\t<input type=\"hidden\" name=\"errorMessage\" value=\"Das hat leider nicht geklappt. Bitte pr\u00fcfen Sie Ihre Angaben und versuchen Sie es erneut.\" \/>\n\n\t\t\t\t\t\t\t\t\t\t\t<div class=\"g-recaptcha\" data-sitekey=\"6LdErNoZAAAAAD1Re2jNxtDFfcDaL9iED5MRBzjR\"\n\t\t\t\t\t\t\tdata-callback=\"verifyRecaptchaCallback\" data-expired-callback=\"expiredRecaptchaCallback\"><\/div>\n\t\t\t\t\t\t<input type=\"hidden\" name=\"g-recaptcha-response\" data-recaptcha \/>\n\t\t\t\t\t\n\t\t\t\t\t<p class=\"lr-cveqc-message\" hidden><\/p>\n\n\t\t\t\t\t<button class=\"lr-button-link\" type=\"submit\">Quick Check starten<\/button>\n\t\t\t\t<\/form>\n\t\t\t<\/div>\n\n\t\t<\/div>\n\t<\/div>\n\n\t\t<style>\n\t\t\/* CVE Quick Check im Stil der bestehenden Anfrage-Formulare:\n\t\t   wei\u00dfer Grund, zweispaltig, graue Felder, t\u00fcrkiser Button. *\/\n\t\t.lr-cveqc {\n\t\t\tbackground: #ffffff; color: #00051d; box-sizing: border-box; padding: 64px 32px;\n\t\t\tfont-family: Roboto, -apple-system, BlinkMacSystemFont, \"Segoe UI\", Helvetica, Arial, sans-serif;\n\t\t}\n\t\t.lr-cveqc * { box-sizing: border-box; }\n\t\t.lr-cveqc-inner {\n\t\t\tmax-width: 1160px; margin: 0 auto;\n\t\t\tdisplay: flex; flex-direction: row; gap: 6%; align-items: flex-start;\n\t\t}\n\t\t.lr-cveqc-story { flex: 1 1 54%; min-width: 0; }\n\t\t.lr-cveqc-form-col { flex: 0 0 38%; max-width: 420px; }\n\n\t\t.lr-cveqc-headline { color: #26d9c3; margin: 0 0 20px; }\n\t\t.lr-cveqc-text { font-size: 16px; line-height: 1.62; color: #00051d; margin: 0 0 28px; max-width: 46ch; }\n\n\t\t.lr-cveqc-bullets { list-style: none; margin: 0 0 30px; padding: 0; display: flex; flex-direction: column; gap: 16px; }\n\t\t.lr-cveqc-bullets li { display: flex; gap: 13px; align-items: flex-start; }\n\t\t.lr-cveqc-bullets svg { flex: none; width: 25px; height: 25px; margin-top: 1px; }\n\t\t.lr-cveqc-bullets span { font-size: 15px; line-height: 1.5; color: #00051d; }\n\n\t\t.lr-cveqc-teaser { border: 1px solid #e2e8e6; border-radius: 12px; padding: 18px 20px; background: linear-gradient(180deg,#fbfdfc,#f2f8f6); max-width: 430px; }\n\t\t.lr-cveqc-teaser h4 { margin: 0 0 6px; font-size: 11px; letter-spacing: .15em; text-transform: uppercase; color: #58616f; font-family: inherit; font-weight: 700; }\n\t\t.lr-cveqc-trow { display: flex; align-items: center; justify-content: space-between; gap: 10px; padding: 7px 0; font-size: 13.5px; }\n\t\t.lr-cveqc-trow + .lr-cveqc-trow { border-top: 1px dashed #dbe4e1; }\n\t\t.lr-cveqc-trow .k { color: #58616f; }\n\t\t.lr-cveqc-trow .v { font-weight: 600; color: #00051d; }\n\t\t.lr-cveqc-lamp { display: inline-flex; gap: 6px; align-items: center; }\n\t\t.lr-cveqc-lamp i { width: 13px; height: 13px; border-radius: 50%; opacity: .28; display: inline-block; }\n\t\t.lr-cveqc-lamp i.r { background: #f6105f; }\n\t\t.lr-cveqc-lamp i.y { background: #f6bf28; }\n\t\t.lr-cveqc-lamp i.g { background: #23c39a; }\n\t\t.lr-cveqc-pill { font-size: 12px; font-weight: 700; padding: 3px 10px; border-radius: 999px; background: #eef0f4; color: #00051d; white-space: nowrap; }\n\n\t\t.lr-cveqc-form input[type=text], .lr-cveqc-form input[type=email], .lr-cveqc-form input[type=tel] {\n\t\t\tdisplay: block; width: 100%; height: 50px; margin: 0 0 10px;\n\t\t\tborder: 0; border-radius: 0; background: #dedede; color: #00051d;\n\t\t\tfont-size: 16px; padding: 0 18px; font-family: inherit;\n\t\t}\n\t\t.lr-cveqc-form input::placeholder { color: #6d7580; }\n\t\t.lr-cveqc-form input.lr-invalid { border-bottom: 2px solid #f6105f; }\n\t\t.lr-cveqc-hint { font-size: 12.5px; line-height: 1.5; color: #58616f; margin: 2px 0 16px; }\n\t\t.lr-cveqc-hp { position: absolute !important; left: -9999px !important; height: 0; overflow: hidden; }\n\t\t.lr-cveqc-check { display: flex; gap: 12px; align-items: flex-start; margin: 0 0 12px; font-size: 12.5px; line-height: 1.5; color: #00051d; }\n\t\t.lr-cveqc-check span { color: #00051d; }\n\t\t.lr-cveqc-check input { margin-top: 2px; flex: none; width: 18px; height: 18px; accent-color: #26d9c3; }\n\t\t.lr-cveqc-check a { color: inherit; text-decoration: underline; }\n\t\t.lr-cveqc .g-recaptcha { margin: 8px 0 16px; }\n\t\t.lr-cveqc-message { font-size: 14px; padding: 12px 14px; border-radius: 6px; margin: 0 0 12px; }\n\t\t.lr-cveqc-message.lr-success { background: #e2f7ef; color: #0c6b4d; }\n\t\t.lr-cveqc-message.lr-error { background: #fdeaee; color: #9b0e3f; }\n\t\t.lr-cveqc .lr-button-link, .lr-cveqc button[type=submit] {\n\t\t\tdisplay: flex; align-items: center; justify-content: center;\n\t\t\twidth: 100%; height: 50px; padding: 0 20px; box-sizing: border-box;\n\t\t\tborder: 0; cursor: pointer;\n\t\t\tbackground: #26d9c3; color: #00051d; font-weight: 700; font-size: 14px;\n\t\t\tfont-family: inherit; text-align: center; line-height: 1.2; text-decoration: none;\n\t\t\ttransition: background .15s ease;\n\t\t}\n\t\t.lr-cveqc button[type=submit]:hover { background: #0fb5a2; }\n\t\t.lr-cveqc button[disabled] { opacity: .6; cursor: default; }\n\n\t\t@media (max-width: 820px) {\n\t\t\t.lr-cveqc { padding: 40px 22px; }\n\t\t\t.lr-cveqc-inner { flex-direction: column; gap: 34px; }\n\t\t\t.lr-cveqc-story, .lr-cveqc-form-col { flex-basis: auto; max-width: 520px; width: 100%; }\n\t\t}\n\t<\/style>\n\t<script>\n\t(function () {\n\t\t\/\/ Token-Callbacks f\u00fcrs globale reCAPTCHA (identisch zum Theme, defensiv)\n\t\tif (!window.verifyRecaptchaCallback) {\n\t\t\twindow.verifyRecaptchaCallback = function (response) {\n\t\t\t\tdocument.querySelectorAll('input[data-recaptcha]').forEach(function (el) { el.value = response })\n\t\t\t}\n\t\t}\n\t\tif (!window.expiredRecaptchaCallback) {\n\t\t\twindow.expiredRecaptchaCallback = function () {\n\t\t\t\tdocument.querySelectorAll('input[data-recaptcha]').forEach(function (el) { el.value = '' })\n\t\t\t}\n\t\t}\n\n\t\tfunction showMessage(form, text, isSuccess) {\n\t\t\tvar box = form.querySelector('.lr-cveqc-message')\n\t\t\tbox.textContent = text\n\t\t\tbox.classList.remove('lr-success', 'lr-error')\n\t\t\tbox.classList.add(isSuccess ? 'lr-success' : 'lr-error')\n\t\t\tbox.hidden = false\n\t\t}\n\n\t\tfunction init() {\n\t\t\tdocument.querySelectorAll('.lr-cveqc-form').forEach(function (form) {\n\t\t\t\tform.addEventListener('submit', function (e) {\n\t\t\t\t\te.preventDefault()\n\n\t\t\t\t\tvar cve = form.querySelector('input[name=cveId]')\n\t\t\t\t\tvar email = form.querySelector('input[name=email]')\n\t\t\t\t\tvar consent = form.querySelector('input[name=consentProcessingAccepted]')\n\t\t\t\t\tvar cvePattern = \/^CVE-\\d{4}-\\d{4,7}$\/i\n\n\t\t\t\t\tcve.classList.toggle('lr-invalid', !cvePattern.test(cve.value.trim()))\n\t\t\t\t\temail.classList.toggle('lr-invalid', !email.checkValidity())\n\n\t\t\t\t\tif (!cvePattern.test(cve.value.trim())) {\n\t\t\t\t\t\tshowMessage(form, form.querySelector('input[name=invalidCveMessage]').value, false)\n\t\t\t\t\t\treturn\n\t\t\t\t\t}\n\t\t\t\t\tif (!email.checkValidity()) {\n\t\t\t\t\t\temail.reportValidity()\n\t\t\t\t\t\treturn\n\t\t\t\t\t}\n\t\t\t\t\tif (!consent.checked) {\n\t\t\t\t\t\tshowMessage(form, form.querySelector('input[name=consentRequiredMessage]').value, false)\n\t\t\t\t\t\treturn\n\t\t\t\t\t}\n\n\t\t\t\t\tvar button = form.querySelector('button[type=submit]')\n\t\t\t\t\tbutton.disabled = true\n\n\t\t\t\t\tvar data = new FormData(form)\n\t\t\t\t\tdata.append('action', 'lr_cve_quick_check')\n\n\t\t\t\t\tfetch(form.getAttribute('data-ajax-url'), { method: 'POST', body: data })\n\t\t\t\t\t\t.then(function (res) { return res.json() })\n\t\t\t\t\t\t.then(function (json) {\n\t\t\t\t\t\t\tif (json && json.success) {\n\t\t\t\t\t\t\t\tshowMessage(form, form.querySelector('input[name=successMessage]').value, true)\n\t\t\t\t\t\t\t\tform.querySelectorAll('input, button').forEach(function (el) { el.disabled = true })\n\t\t\t\t\t\t\t} else {\n\t\t\t\t\t\t\t\t\/\/ Interne Codes nie roh anzeigen, nur bekannte Codes auf\n\t\t\t\t\t\t\t\t\/\/ konfigurierte Texte mappen, sonst generische Fehlermeldung\n\t\t\t\t\t\t\t\tvar code = json && json.data && (json.data.code || json.data.message)\n\t\t\t\t\t\t\t\tvar msg = form.querySelector('input[name=errorMessage]').value\n\t\t\t\t\t\t\t\tif (code === 'invalid_cve' || code === 'invalid') {\n\t\t\t\t\t\t\t\t\tmsg = form.querySelector('input[name=invalidCveMessage]').value\n\t\t\t\t\t\t\t\t} else if (code === 'captcha') {\n\t\t\t\t\t\t\t\t\tmsg = form.querySelector('input[name=captchaMessage]').value\n\t\t\t\t\t\t\t\t}\n\t\t\t\t\t\t\t\tshowMessage(form, msg, false)\n\t\t\t\t\t\t\t\tbutton.disabled = false\n\t\t\t\t\t\t\t\tif (window.grecaptcha && form.querySelector('.g-recaptcha')) {\n\t\t\t\t\t\t\t\t\ttry { window.grecaptcha.reset() } catch (err) { \/* noop *\/ }\n\t\t\t\t\t\t\t\t}\n\t\t\t\t\t\t\t}\n\t\t\t\t\t\t})\n\t\t\t\t\t\t.catch(function () {\n\t\t\t\t\t\t\tshowMessage(form, form.querySelector('input[name=errorMessage]').value, false)\n\t\t\t\t\t\t\tbutton.disabled = false\n\t\t\t\t\t\t})\n\t\t\t\t})\n\t\t\t})\n\t\t}\n\n\t\tif (document.readyState === 'loading') {\n\t\t\tdocument.addEventListener('DOMContentLoaded', init)\n\t\t} else {\n\t\t\tinit()\n\t\t}\n\t})()\n\t<\/script>\n\t\n\n\n\n<hr class=\"wp-block-separator has-css-opacity is-style-wide\"\/>\n\n\n\n<div class=\"wp-block-lr-contact-module\"><div class=\"content\"><h2>Mehr erfahren, Demo buchen oder einfach mal kurz austauschen? Wir freuen uns!<\/h2><div class=\"contact-info-row\"><div class=\"contact-person-info\"><div class=\"avatar\"><img decoding=\"async\" src=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2025\/06\/Lukas_Baumann_LocateRisk-300.png\"><\/div><p><span class=\"text before\">Ihr Ansprechpartner<\/span><span class=\"bold name\"><strong>Lukas<\/strong><\/span> <span class=\"lastname\"><strong>Baumann<strong><\/strong><\/strong><\/span><strong><strong><span class=\"separator\"><\/span><span class=\"role\">CEO<\/span><\/strong><\/strong><\/p><\/div><p class=\"bold phone\"><strong><strong>+49 6151 6290246<\/strong><\/strong><\/p><strong><strong><a class=\"pr-1\" href=\"mailto:%20sales@locaterisk.com\">Jetzt Kontakt aufnehmen<\/a><\/strong><\/strong><\/div><\/div><\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<div class=\"wp-block-lr-footer-module lr-footer-block\"><div class=\"content\"><div class=\"column0\"><img decoding=\"async\" src=\"https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/assets\/img\/lr-logo.svg\"\/><\/div><div class=\"categories\"><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/locaterisk.com\/fr\/\">Home<\/a><\/div><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/locaterisk.com\/fr\/blog\/\">Blog<\/a><\/div><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/locaterisk.com\/fr\/savoir\/\">Wissen<\/a><\/div><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/locaterisk.com\/fr\/a-propos\/\">\u00dcber uns<\/a><\/div><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/locaterisk.com\/fr\/contact\/\">Kontakt<\/a><\/div><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/locaterisk.com\/fr\/mentions-legales\/\">Impressum<\/a><\/div><div class=\"categories-break\"><\/div><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/locaterisk.com\/fr\/protection-des-donnees\/\">Datenschutz<\/a><\/div><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/locaterisk.com\/files\/agb.pdf\">AGB<\/a><\/div><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/locaterisk.com\/fr\/offres-demploi\/\">Jobs<\/a><\/div><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/app.secfix.com\/trust\/locaterisk\/d1e7d433b33643aea1880bfbfeab9f60\">Trust Center<\/a><\/div><\/div><div class=\"social\"><div class=\"social-element\"><a target=\"_blank\" href=\"https:\/\/www.linkedin.com\/company\/locaterisk\/\"><img decoding=\"async\" src=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/10\/gruppe-230@3x.png\"\/><\/a><\/div><div class=\"social-element\"><a target=\"_blank\" href=\"https:\/\/www.instagram.com\/locaterisk\/\"><img decoding=\"async\" src=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Instagram.png\"\/><\/a><\/div><div class=\"social-element\"><a target=\"_blank\" href=\"https:\/\/twitter.com\/locaterisk\"><img decoding=\"async\" src=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/twitter.png\"\/><\/a><\/div><\/div><div class=\"description\"><h6>\u00a9 LocateRisk 2026<\/h6><\/div><\/div><\/div>\n\n\n\n<style id=\"lr-ol-fix\">body>div>ol,.entry-content>div>ol{max-width:843px;margin:0 auto;padding:20px 0;font-family:Roboto;font-size:1.25rem;line-height:1.67;color:#ffffff}.blog-post ol.wp-block-list{padding-left:3rem}<\/style>\n","protected":false},"excerpt":{"rendered":"<p>Trois vuln\u00e9rabilit\u00e9s critiques dans @zereight\/mcp-gitlab concernent des points de terminaison MCP non s\u00e9curis\u00e9s, une fuite de jetons et du DNS rebinding.<\/p>","protected":false},"author":13,"featured_media":9138,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[632],"tags":[925,919,921,920,924,923,922],"lr_blog_topic":[837],"class_list":["post-99153","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-news","tag-zereight-mcp-gitlab","tag-cve-2026-61559","tag-cve-2026-61560","tag-cve-2026-61568","tag-gitlab-mcp","tag-mcp-server","tag-npm-sicherheit","lr_blog_topic-schwachstellen-advisories"],"yoast_head":"<title>CVE-2026-61560: Kritische Schwachstellen in GitLab-MCP<\/title>\n<meta name=\"description\" content=\"Drei kritische Schwachstellen in @zereight\/mcp-gitlab betreffen ungesch\u00fctzte MCP-Endpunkte, Token-Abfluss und DNS-Rebinding.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/locaterisk.com\/fr\/zereight-mcp-gitlab-cve-2026-61560\/\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"CVE-2026-61560: Kritische Schwachstellen in GitLab-MCP\" \/>\n<meta property=\"og:description\" content=\"Drei kritische Schwachstellen in @zereight\/mcp-gitlab betreffen ungesch\u00fctzte MCP-Endpunkte, Token-Abfluss und DNS-Rebinding.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/locaterisk.com\/fr\/zereight-mcp-gitlab-cve-2026-61560\/\" \/>\n<meta property=\"og:site_name\" content=\"LocateRisk\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-15T23:22:04+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/vulnerability-disclosure.png\" \/>\n\t<meta property=\"og:image:width\" content=\"400\" \/>\n\t<meta property=\"og:image:height\" content=\"400\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Kristina Hoinkis\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u00c9crit par\" \/>\n\t<meta name=\"twitter:data1\" content=\"Kristina Hoinkis\" \/>\n\t<meta name=\"twitter:label2\" content=\"Dur\u00e9e de lecture estim\u00e9e\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/zereight-mcp-gitlab-cve-2026-61560\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/zereight-mcp-gitlab-cve-2026-61560\\\/\"},\"author\":{\"name\":\"Kristina Hoinkis\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/person\\\/68f3857c15afa8ff59c545848dddcc32\"},\"headline\":\"CVE-2026-61560: Drei kritische Schwachstellen in GitLab-MCP\",\"datePublished\":\"2026-09-15T23:22:04+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/zereight-mcp-gitlab-cve-2026-61560\\\/\"},\"wordCount\":1161,\"publisher\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/zereight-mcp-gitlab-cve-2026-61560\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/vulnerability-disclosure.png\",\"keywords\":[\"@zereight\\\/mcp-gitlab\",\"CVE-2026-61559\",\"CVE-2026-61560\",\"CVE-2026-61568\",\"GitLab MCP\",\"MCP-Server\",\"npm-Sicherheit\"],\"articleSection\":[\"Cybersecurity News\"],\"inLanguage\":\"fr-FR\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/zereight-mcp-gitlab-cve-2026-61560\\\/\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/zereight-mcp-gitlab-cve-2026-61560\\\/\",\"name\":\"CVE-2026-61560: Kritische Schwachstellen in GitLab-MCP\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/zereight-mcp-gitlab-cve-2026-61560\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/zereight-mcp-gitlab-cve-2026-61560\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/vulnerability-disclosure.png\",\"datePublished\":\"2026-09-15T23:22:04+00:00\",\"description\":\"Drei kritische Schwachstellen in @zereight\\\/mcp-gitlab betreffen ungesch\u00fctzte MCP-Endpunkte, Token-Abfluss und DNS-Rebinding.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/zereight-mcp-gitlab-cve-2026-61560\\\/#breadcrumb\"},\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/locaterisk.com\\\/de\\\/zereight-mcp-gitlab-cve-2026-61560\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/zereight-mcp-gitlab-cve-2026-61560\\\/#primaryimage\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/vulnerability-disclosure.png\",\"contentUrl\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/vulnerability-disclosure.png\",\"width\":400,\"height\":400,\"caption\":\"vulnerability-disclosure\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/zereight-mcp-gitlab-cve-2026-61560\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/locaterisk.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"CVE-2026-61560: Drei kritische Schwachstellen in GitLab-MCP\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#website\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/\",\"name\":\"LocateRisk\",\"description\":\"IT-Sicherheit messen und vergleichen\",\"publisher\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"fr-FR\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#organization\",\"name\":\"LocateRisk\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/Kettenglieder_V0216-9.jpg\",\"contentUrl\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/Kettenglieder_V0216-9.jpg\",\"width\":1920,\"height\":1080,\"caption\":\"LocateRisk\"},\"image\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/locaterisk\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/person\\\/68f3857c15afa8ff59c545848dddcc32\",\"name\":\"Kristina Hoinkis\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7756f96249844e60ceb218f17e06217dcbed4993bcd2124e3f59bb8675324f0d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7756f96249844e60ceb218f17e06217dcbed4993bcd2124e3f59bb8675324f0d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7756f96249844e60ceb218f17e06217dcbed4993bcd2124e3f59bb8675324f0d?s=96&d=mm&r=g\",\"caption\":\"Kristina Hoinkis\"}}]}<\/script>","yoast_head_json":{"title":"CVE-2026-61560: Vuln\u00e9rabilit\u00e9s critiques dans GitLab-MCP","description":"Trois vuln\u00e9rabilit\u00e9s critiques dans @zereight\/mcp-gitlab concernent des points de terminaison MCP non s\u00e9curis\u00e9s, une fuite de jetons et du DNS rebinding.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/locaterisk.com\/fr\/zereight-mcp-gitlab-cve-2026-61560\/","og_locale":"fr_FR","og_type":"article","og_title":"CVE-2026-61560: Kritische Schwachstellen in GitLab-MCP","og_description":"Drei kritische Schwachstellen in @zereight\/mcp-gitlab betreffen ungesch\u00fctzte MCP-Endpunkte, Token-Abfluss und DNS-Rebinding.","og_url":"https:\/\/locaterisk.com\/fr\/zereight-mcp-gitlab-cve-2026-61560\/","og_site_name":"LocateRisk","article_published_time":"2026-09-15T23:22:04+00:00","og_image":[{"width":400,"height":400,"url":"https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/vulnerability-disclosure.png","type":"image\/png"}],"author":"Kristina Hoinkis","twitter_card":"summary_large_image","twitter_misc":{"\u00c9crit par":"Kristina Hoinkis","Dur\u00e9e de lecture estim\u00e9e":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/locaterisk.com\/de\/zereight-mcp-gitlab-cve-2026-61560\/#article","isPartOf":{"@id":"https:\/\/locaterisk.com\/de\/zereight-mcp-gitlab-cve-2026-61560\/"},"author":{"name":"Kristina Hoinkis","@id":"https:\/\/locaterisk.com\/de\/#\/schema\/person\/68f3857c15afa8ff59c545848dddcc32"},"headline":"CVE-2026-61560: Drei kritische Schwachstellen in GitLab-MCP","datePublished":"2026-09-15T23:22:04+00:00","mainEntityOfPage":{"@id":"https:\/\/locaterisk.com\/de\/zereight-mcp-gitlab-cve-2026-61560\/"},"wordCount":1161,"publisher":{"@id":"https:\/\/locaterisk.com\/de\/#organization"},"image":{"@id":"https:\/\/locaterisk.com\/de\/zereight-mcp-gitlab-cve-2026-61560\/#primaryimage"},"thumbnailUrl":"https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/vulnerability-disclosure.png","keywords":["@zereight\/mcp-gitlab","CVE-2026-61559","CVE-2026-61560","CVE-2026-61568","GitLab MCP","MCP-Server","npm-Sicherheit"],"articleSection":["Cybersecurity News"],"inLanguage":"fr-FR"},{"@type":"WebPage","@id":"https:\/\/locaterisk.com\/de\/zereight-mcp-gitlab-cve-2026-61560\/","url":"https:\/\/locaterisk.com\/de\/zereight-mcp-gitlab-cve-2026-61560\/","name":"CVE-2026-61560: Vuln\u00e9rabilit\u00e9s critiques dans GitLab-MCP","isPartOf":{"@id":"https:\/\/locaterisk.com\/de\/#website"},"primaryImageOfPage":{"@id":"https:\/\/locaterisk.com\/de\/zereight-mcp-gitlab-cve-2026-61560\/#primaryimage"},"image":{"@id":"https:\/\/locaterisk.com\/de\/zereight-mcp-gitlab-cve-2026-61560\/#primaryimage"},"thumbnailUrl":"https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/vulnerability-disclosure.png","datePublished":"2026-09-15T23:22:04+00:00","description":"Trois vuln\u00e9rabilit\u00e9s critiques dans @zereight\/mcp-gitlab concernent des points de terminaison MCP non s\u00e9curis\u00e9s, une fuite de jetons et du DNS rebinding.","breadcrumb":{"@id":"https:\/\/locaterisk.com\/de\/zereight-mcp-gitlab-cve-2026-61560\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/locaterisk.com\/de\/zereight-mcp-gitlab-cve-2026-61560\/"]}]},{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/locaterisk.com\/de\/zereight-mcp-gitlab-cve-2026-61560\/#primaryimage","url":"https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/vulnerability-disclosure.png","contentUrl":"https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/vulnerability-disclosure.png","width":400,"height":400,"caption":"vulnerability-disclosure"},{"@type":"BreadcrumbList","@id":"https:\/\/locaterisk.com\/de\/zereight-mcp-gitlab-cve-2026-61560\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/locaterisk.com\/"},{"@type":"ListItem","position":2,"name":"CVE-2026-61560: Drei kritische Schwachstellen in GitLab-MCP"}]},{"@type":"WebSite","@id":"https:\/\/locaterisk.com\/de\/#website","url":"https:\/\/locaterisk.com\/de\/","name":"LocateRisk","description":"Mesurer et comparer la s\u00e9curit\u00e9 informatique","publisher":{"@id":"https:\/\/locaterisk.com\/de\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/locaterisk.com\/de\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"fr-FR"},{"@type":"Organization","@id":"https:\/\/locaterisk.com\/de\/#organization","name":"LocateRisk","url":"https:\/\/locaterisk.com\/de\/","logo":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/locaterisk.com\/de\/#\/schema\/logo\/image\/","url":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_V0216-9.jpg","contentUrl":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_V0216-9.jpg","width":1920,"height":1080,"caption":"LocateRisk"},"image":{"@id":"https:\/\/locaterisk.com\/de\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/locaterisk\/"]},{"@type":"Person","@id":"https:\/\/locaterisk.com\/de\/#\/schema\/person\/68f3857c15afa8ff59c545848dddcc32","name":"Kristina Hoinkis","image":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/secure.gravatar.com\/avatar\/7756f96249844e60ceb218f17e06217dcbed4993bcd2124e3f59bb8675324f0d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/7756f96249844e60ceb218f17e06217dcbed4993bcd2124e3f59bb8675324f0d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/7756f96249844e60ceb218f17e06217dcbed4993bcd2124e3f59bb8675324f0d?s=96&d=mm&r=g","caption":"Kristina Hoinkis"}}]}},"_links":{"self":[{"href":"https:\/\/locaterisk.com\/fr\/wp-json\/wp\/v2\/posts\/99153","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/locaterisk.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/locaterisk.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/locaterisk.com\/fr\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/locaterisk.com\/fr\/wp-json\/wp\/v2\/comments?post=99153"}],"version-history":[{"count":1,"href":"https:\/\/locaterisk.com\/fr\/wp-json\/wp\/v2\/posts\/99153\/revisions"}],"predecessor-version":[{"id":99154,"href":"https:\/\/locaterisk.com\/fr\/wp-json\/wp\/v2\/posts\/99153\/revisions\/99154"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/locaterisk.com\/fr\/wp-json\/wp\/v2\/media\/9138"}],"wp:attachment":[{"href":"https:\/\/locaterisk.com\/fr\/wp-json\/wp\/v2\/media?parent=99153"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/locaterisk.com\/fr\/wp-json\/wp\/v2\/categories?post=99153"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/locaterisk.com\/fr\/wp-json\/wp\/v2\/tags?post=99153"},{"taxonomy":"lr_blog_topic","embeddable":true,"href":"https:\/\/locaterisk.com\/fr\/wp-json\/wp\/v2\/lr_blog_topic?post=99153"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}