A vulnerability, which was classified as problematic, was found in yoda.digital gitlab-mcp-server. This vulnerability affects unknown code. Such manipulation leads to permissive cross-domain policy with untrusted domains.
This vulnerability is referenced as CVE-2026-44895. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.