CVE-2026-61462EPSS p41.4%
CVE-2026-61462CVE-2026-61462
Description
mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints. Attackers can supply crafted job_id values like ../../../user to escape the intended path prefix and access arbitrary GitLab API resources using the operator's personal access token.
Scoring
| CVSS | 8.6 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
| EPSS | 0.51% probability of exploitation · percentile 41.4% · 2026-10-06T12:00:23Z |
| Last modified | 2026-07-13 |