GHSA-8jr5-6gvj-rfpf
HIGHCVE-2026-44895A review of mcp-gitlab-server at commit 80a7b4cf3fba6b55389c0ef491a48190f7c8996a uncovered that the SSE HTTP transport — advertised in the README and comparison table as a differentiating feature — runs with no authentication and wildcard CORS on every endpoint. The maintainers' own roadmap confirms auth is a known gap.
- Affected
- >=0, <0.6.0, < 0.6.0
- Fixed in
- 0.6.0
- Weakness
- CWE-306
- Published
- 2026-05-09
- Source
- osv