Wednesday, 16 September 2026
0 agent hacks today 2 vs yesterday (2)

@zereight/mcp-gitlab Multiple Safety Control Bypasses

@zereight/mcp-gitlab contains five defects that defeat its safety controls for exposing GitLab to LLM agents, including read-only mode bypasses, unauthenticated transports, DNS rebinding vulnerabilities, session exhaustion DoS, and SSRF via header injection.

Disclosed 15 September 2026 · Record updated 15 September 2026

Impact

Attackers can bypass read-only protections, execute unauthorized GraphQL mutations, conduct DNS rebinding attacks, exhaust sessions via DoS, steal GitLab credentials via SSRF, and exfiltrate sensitive CI job data through prompt injection surfaces.

Our coverage

Sources

  1. github.comhttps://github.com/advisories/GHSA-5648-rgj9-v224
  2. github.comhttps://github.com/advisories/GHSA-vmp7-252j-cwp7
  3. github.comhttps://github.com/advisories/GHSA-2h44-8472-frjj