VULNRABLE / Vulnerability / GHSA-5648-rgj9-v224
GHSA-5648-rgj9-v224
HIGH LOW @zereight/mcp-gitlab GHSA
Exploit verdict: No active-exploit signal
CVSS Score
8
Severity
HIGH
EPSS
—
Source
GHSA
Summary
@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhau...
What this means
GHSA-5648-rgj9-v224 is a high-severity vulnerability affecting @zereight/mcp-gitlab, rated CVSS 8. Published September 16, 2026.
View full advisory at GHSA →