{"data":{"id":"4a577249-3a47-45a1-886c-2202bbc50953","title":"GHSA-5648-rgj9-v224: @zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS","summary":"The @zereight/mcp-gitlab package, which connects GitLab to an AI agent, has five security flaws that bypass its safety controls (read-only mode, project allow-lists, and authentication). These flaws let attackers execute write operations through GraphQL, access the tool without credentials, perform DNS rebinding attacks, exhaust sessions with fake tokens, and inject malicious instructions through CI job logs.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-5648-rgj9-v224","publishedAt":"2026-09-15T20:48:22.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":["prompt_injection","rag_poisoning","denial_of_service"],"issueType":"vulnerability","affectedPackages":["@zereight/mcp-gitlab@< 2.1.30 (fixed: 2.1.30)"],"affectedVendors":["LangChain"],"affectedVendorsRaw":["@zereight/mcp-gitlab","GitLab","MCP (Model Context Protocol)"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":true,"disclosureDate":"2026-09-15T20:48:22.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}