CyberSec.Space Logo
Back to CVE Browser

CVE-2026-61462

HIGH
8.6
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2026-07-13
Last Modified2026-07-13
Data SourcesNVD

Vulnerability Description

mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints. Attackers can supply crafted job_id values like ../../../user to escape the intended path prefix and access arbitrary GitLab API resources using the operator's personal access token.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

Related Vulnerabilities