@yoda.digital/gitlab-mcp-server@0.2.10

GitLab MCP Server - A Model Context Protocol server for GitLab integration

  • latest version

    0.8.0

  • latest non vulnerable version

  • first published

    1 years ago

  • latest version published

    9 hours ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @yoda.digital/gitlab-mcp-server package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Permissive Cross-domain Policy with Untrusted Domains

    @yoda.digital/gitlab-mcp-server is a GitLab MCP Server - A Model Context Protocol server for GitLab integration

    Affected versions of this package are vulnerable to Permissive Cross-domain Policy with Untrusted Domains via the SSE HTTP transport when USE_SSE=true is set, which lacks authentication and uses a wildcard CORS policy. An attacker can gain unauthorized access to all available GitLab tools and perform destructive operations by sending unauthenticated requests to the exposed endpoints from any network location or cross-origin browser context. This is only exploitable if the server is running with USE_SSE=true and is accessible from the attacker's network or browser context.

    How to fix Permissive Cross-domain Policy with Untrusted Domains?

    Upgrade @yoda.digital/gitlab-mcp-server to version 0.6.0 or higher.

    <0.6.0