CVE-2026-61462
zereight mcp-gitlab 취약점
mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints. Attackers can supply crafted job_id values like ../../../user to escape the intended path prefix and access arbitrary GitLab API resources using the operator's personal access token.
- 대응 우선순위
- 점검
- CVSS
- 9.2
- EPSS
- 0.38% 백분위 30.2% · 2026.07.15 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.07.14