CVE-2026-61462 CRITICAL

CVE-2026-61462: mcp-gitlab Path Traversal via job_id Parameter

Vendor Zereight
Product mcp-gitlab
Weakness CWE-73
Published July 13, 2026
Last update July 20, 2026

CVSS base score

9.2/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N

What the vulnerability does

01Description

mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints. Attackers can supply crafted job_id values like ../../../user to escape the intended path prefix and access arbitrary GitLab API resources using the operator's personal access token.

Key dates

02Disclosure timeline

July 13, 2026 CVE published
July 20, 2026 Record updated

Related vulnerabilities

04Related CVE