Integrates with GitLab's API to manage projects, issues, merge requests, pipelines, and CI/CD workflows with 22 specialized tools including pipeline control, job log analysis, branch browsing, and user management.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
form-data uses unsafe random function in form-data for choosing boundary
When Vitest UI server is listening, arbitrary file can be read and executed
Vitest allows Remote Code Execution when accessing a malicious website while Vitest API server is listening
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
process.env. You'll be asked to provide them before it can run.GITLAB_ACCESS_TOKENGITLAB_BASE_URL— "": "https://gitlab.mycompany.com"GITLAB_DEFAULT_PROJECTGITLAB_MCP_CONFIGGITLAB_MCP_ENABLE_CACHINGGITLAB_MCP_ENABLE_METRICSGITLAB_MCP_PER_PAGEGITLAB_MCP_PROJECT_SCOPEGITLAB_MCP_STRICT_SCOPINGGITLAB_MCP_TIMEOUTGITLAB_TOKENNPM_CONFIG_BASE_URLNPM_CONFIG_TOKEN— "": "your-gitlab-token-here"[](https://m8ven.ai/mcp/alosies-gitlab-mcp-server-y2ktx0)