@zereight/mcp-gitlab npm Package SSRF Vulnerability
- Severity
- HIGH
- CVSS
- 8.5 (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N)
- Affected component
- @zereight/mcp-gitlab (npm)
- Affected versions
- < 2.1.30 or < 2.1.30
- Patched version
- Not yet available
An early warning has been issued for a high-severity Server-Side Request Forgery (SSRF) vulnerability in the @zereight/mcp-gitlab npm package. This vulnerability, tracked as GHSA-2H44-8472-FRJJ, could allow credential theft.
What happened
The @zereight/mcp-gitlab npm package is reportedly vulnerable to Server-Side Request Forgery (SSRF) via the X-GitLab-API-URL header. This vulnerability, identified as GHSA-2H44-8472-FRJJ, could potentially allow an attacker to steal credentials. The vulnerability affects all versions of the package up to commit 74a8c83. The CVSS score for this vulnerability is 8.5, indicating a high severity.
The vulnerability is under investigation and has not been exploited in the wild as of the latest reports. It is crucial for users of the @zereight/mcp-gitlab package to assess their exposure and take appropriate action to mitigate potential risks.
What to do about it
- Avoid setting the ENABLE_DYNAMIC_API_URL environment variable to true.
- Upgrade to a patched version of @zereight/mcp-gitlab when it becomes available.
- Monitor the primary sources for updates on the vulnerability and any available patches.
- Consult the primary sources for the most current information on affected versions and recommended actions.
How 0Day would have caught this
@zereight/mcp-gitlab is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if you are using @zereight/mcp-gitlab npm package in versions less than 2.1.30.
What should I do right now?
Avoid setting the ENABLE_DYNAMIC_API_URL environment variable to true and monitor the primary sources for updates on the vulnerability and any available patches.
Is there a patched version available?
No official fix has been published yet. Monitor the sources for updates.