← Πίσω στην αναζήτηση CVE

CVE-2026-61462

mcp-gitlab

Περιγραφή

mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints. Attackers can supply crafted job_id values like ../../../user to escape the intended path prefix and access arbitrary GitLab API resources using the operator-s personal access token.

CVSS 8.6EPSS 0.38%Κίνδυνος 0.89
Προβολή πηγής
Δημοσίευση
2026-07-13 18:16:29
Επηρεαζόμενες εκδόσεις
unknown
Τύπος
Εφαρμογή ιστού
Διάνυσμα
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N