Vibe Coding
GitLab 19.4.1 patches an MCP-scoped token that could act beyond its scope, plus an MCP search race that leaked results
GitLab shipped the critical patch releases 19.4.1, 19.3.3 and 19.2.7 on 2026-09-23. CVE-2026-92874 (CVSS 5.4, affects 18.3 onward) let an authenticated user holding an MCP-scoped token perform actions outside that token's intended scope, because authorization checks were missing. CVE-2026-92628 (CVSS 3.1, affects 18.6 onward) is a race condition in the MCP search tool's shared state that could return search results to the wrong user. GitLab.com is already patched. Self-managed instances that expose GitLab's MCP server to agents should upgrade.
↳ Follow the thread