@zereight/mcp-gitlab is vulnerable to Path Traversal
98
Critical Risk
The SSE transport exposes all MCP tools with no authentication, and the upload_markdown tool reads a file from an unvalidated file_path argument before uploading it to a GitLab project. An unauthenticated network-reachable caller can chain these to read arbitrary local files such as /proc/self/environ and exfiltrate the server's GitLab personal access token, leading to full account takeover. This is reachable in the default Docker deployment, where the process runs as root and the port is network-exposed. The fix adds an SSE authentication guard and blocks remote file_path input to upload_markdown.
You are affected if you are using a version that falls within the vulnerable range and you run the SSE transport with the upload_markdown tool enabled.
@zereight/mcp-gitlab is vulnerable to Path Traversal in versions 0.0.1 - 2.1.26.
Upgrade the @zereight/mcp-gitlab library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant