Vulnerability Research

24 published disclosures, disclosed through GitHub Security Advisories. Every entry links to its advisory and fix; technical writeups are added as each disclosure clears. Filter by severity, year or ecosystem, or search the text.

Severity
Year
Ecosystem

Published advisories

CVE-2026-61559 9.6critical

@zereight/mcp-gitlab vulnerable to server-side request forgery

Unvalidated user-controlled URLs in the GitLab MCP server let an attacker make the host issue requests to arbitrary destinations, reaching internal services.

CWE-918
@zereight/mcp-gitlabaffects >= 0.0.1, < 2.1.272026-09-15
CVE-2026-55642 9.8critical

Unauthenticated arbitrary SQL execution in dbx-web

dbx-web fails open when no password is configured: authentication is skipped entirely, so an unauthenticated client can execute arbitrary SQL against connected databases.

CWE-306
t8y2/dbxaffects <= 0.5.502026-07-11