@zereight/mcp-gitlab: unauthenticated MCP → local file read → GitLab token theft (opens in a new tab)
GitHub Security Advisory
A critical vulnerability in @zereight/mcp-gitlab allowed an unauthenticated attacker to read arbitrary local files through an exposed MCP tool and potentially recover the GitLab access token used by the server.