CVE-2026-44895: GitLab MCP Server HTTP transport exposes unauthenticated RPC endpoint
Prior to version 0.6.0, the GitLab MCP Server's HTTP/SSE transport shipped with no inbound authentication, a wildcard Access-Control-Allow-Origin header, and a default bind to 0.0.0.0, exposing a mutation-capable RPC endpoint backed by the operator's GitLab personal access token. The issue is fixed in 0.6.0.
Disclosed 26 May 2026 · Record updated 13 September 2026
Impact
Any cross-origin browser context or network peer could reach the unauthenticated endpoint and perform GitLab operations using the operator's personal access token.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-44895
