Database/Control plane, storage & DevOps
GitLab: MCP-scoped tokens can act beyond their intended scope
Impact
Improper authorization checks let an authenticated user holding an MCP-scoped token perform actions the token's scope was not meant to permit. MCP tokens are the credential handed to LLM agents and agent tooling wired into a self-hosted GitLab, so the practical exposure is an agent integration - or anyone who obtains its token - reaching repository or project operations the operator deliberately fenced off when issuing it. On a fleet where GitLab is the CI/CD control plane for cluster manifests and model pipelines, scope creep on an automation credential is a change-control problem. The advisory rates it low confidentiality and integrity impact and does not describe which actions become reachable.
Who can reach it
An authenticated GitLab user or automation holding an MCP-scoped token, over the network to the GitLab instance. No admin role needed.
What to do
Upgrade self-managed GitLab to 19.2.7, 19.3.3, or 19.4.1 depending on your branch (all versions from 18.3 are affected). This is the standard GitLab patch release: package upgrade plus a service restart and migrations on the GitLab host, no cluster-wide disruption. GitLab.com is already patched. Consider rotating MCP-scoped tokens after upgrading.
References
Related entries
- CloudNativePG instance manager (status server, TCP/8000 control endpoints): A set of operator-only control endpointsNCVD-2026-050-cloudnativepg-instance-manager-s · CloudNativePG instance manager (status server, TCP/8000 control endpoints)Medium
- Slurm (user_name / gid field handling): Slurm trusts the user_name and gid fields carried in job RPCs instead ofCVE-2018-10995 · Slurm (user_name / gid field handling)Medium
- IBM Spectrum LSF (job submission, file permissions): Weak file permissions in the LSF install let a local user changeCVE-2018-1724 · IBM Spectrum LSF (job submission, file permissions)Medium
- AMD IOMMU host buffer access - insufficient RMP checks (AMD-SB-3016): Insufficient RMP checking on IOMMU host bufferCVE-2023-20585 · AMD IOMMU host buffer access - insufficient RMP checks (AMD-SB-3016)Medium
- ZKTeco BioAccess IVS v3.3.1 access control platform: An unauthenticated attacker can open and close any doorCVE-2023-38958 · ZKTeco BioAccess IVS v3.3.1 access control platformMedium
- Intel Data Center GPU Flex Series - Windows driver software: Improper access control in the Flex Series Windows driverCVE-2024-43101 · Intel Data Center GPU Flex Series - Windows driver softwareMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.