Junglewise Threat Intelligence

CVE-2026-44895: Yoda Digital GitLab MCP Server missing authentication in SSE transport

CVE-2026-44895 · Severity: high · CVSS 4 · Published 2026-05-26

Vendors: npm.

Executive brief

The GitLab MCP Server, a tool used to integrate GitLab functionality with AI agents, contains a security flaw in its Server-Sent Events (SSE) transport mode. When this mode is enabled, the server lacks any authentication and allows requests from any website via a wildcard CORS policy. This allows an attacker or a malicious website to perform actions on your GitLab account, such as deleting repositories or modifying code, using your saved access credentials.

Technical details

The vulnerability exists in the SSE HTTP transport implementation within `src/transport.ts`. When `USE_SSE=true` is configured, the server fails to implement any authentication checks on the `/sse` and `/messages` endpoints. Furthermore, it sets `Access-Control-Allow-Origin: *` and binds to `0.0.0.0` by default. This combination allows any network-adjacent attacker or a malicious website visited by the operator to interact with the Model Context Protocol (MCP) server. Since the server uses the operator's `GITLAB_PERSONAL_ACCESS_TOKEN` to execute commands, an attacker can perform destructive operations like `delete_repository` or `push_files`. The issue is addressed in version 0.6.0 by requiring an auth token and restricting default network binding.

Affected products

  • yoda-digital @yoda.digital/gitlab-mcp-server < 0.6.0

Timeline

  • 2026-05-06: disclosed: Advisory published by researcher
  • 2026-05-09: advisory: GitHub Advisory published
  • 2026-06-08: other: Advisory updated

References