CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

yoda-digital mcp-gitlab-server < 0.6.0, no-auth SSE RPC endpoint bound to 0.0.0.0 with wildcard CORS exposes operator GitLab PAT (CVSS 4.0 = 9.2; GHSA-8jr5-6gvj-rfpf); noted in § 7 (niche package)

cve · CVE-2026-44895

Coverage
0
first 2026-05-27 → last 2026-05-27
no data
Latest activity
–
no entry about it yet
Peak priority
·
no entry about it yet
Targets
·
no sector or region stated
Sources cited
0
0 hosts

Story timeline

No published entries reference this entity yet.

Entries about yoda-digital mcp-gitlab-server < 0.6.0, no-auth SSE RPC endpoint bound to 0.0.0.0 with wildcard CORS exposes operator GitLab PAT (CVSS 4.0 = 9.2; GHSA-8jr5-6gvj-rfpf); noted in § 7 (niche package)

No published entry is about this entity yet · an entry attaches by registry key, by the entity's name or a public alias in its title or body, or (for CVE entities) by exact CVE id.

explore in graph

External references

NVD · cve.org · CISA KEV