4 Total advisories
4 Vulnerabilities
0 Malware
Dependency scanning
Check whether @zereight/mcp-gitlab is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CRITICAL 9.8
CVE-2026-61560
@zereight/mcp-gitlab: Unauthenticated arbitrary file read via `upload_markdown` enables PAT exfiltration and full account takeover
CRITICAL 9.6
CVE-2026-61559
@zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery
CRITICAL 9.6
CVE-2026-61568
@zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport
HIGH 8.1
GHSA-5648-rgj9-v224
@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes