Enables AI agents to interact with GitLab repositories, issues, merge requests, pipelines, wikis, milestones, and more through the GitLab API.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
form-data uses unsafe random function in form-data for choosing boundary
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
form-data: CRLF injection in form-data via unescaped multipart field names and filenames
esbuild allows arbitrary file read when running the development server on Windows
process.env. You'll be asked to provide them before it can run.DEFAULT_NULLDISCUSSION_IDGITLAB_ALLOWED_PROJECT_IDS— "": "", // Optional: comma-separated list of allowed project IDsGITLAB_API_URL— "": "your_gitlab_api_url",GITLAB_COMMIT_FILES_PER_PAGEGITLAB_GRAPHQL_URLGITLAB_OAUTH_CLIENT_ID— "": "your_oauth_client_id",GITLAB_OAUTH_CLIENT_SECRET— "": "your_oauth_client_secret", // Required for Confidential apps onlyGITLAB_OAUTH_REDIRECT_URI— "": "http://127.0.0.1:8888/callback",GITLAB_OAUTH_TOKEN_PATH— Custom path to store the OAuth token. Default: ~/.gitlab-mcp-token.jsonGITLAB_PROJECT_ID— "": "your_project_id", // Optional: default projectGITLAB_READ_ONLY_MODE— "": "false",GITLAB_TOKENISSUE_IIDLOG_LEVELMAX_REQUESTS_PER_MINUTE— Rate limit per session in requests per minute. Default: 60. Valid range: 1-1000. Exceeded requests return HTTP 429.MAX_SESSIONS— Maximum number of concurrent sessions allowed. Default: 1000. Valid range: 1-10000. When limit is reached, new connections are rejected with HTTP 503.NOTE_IDPROJECT_IDSESSION_TIMEOUT_SECONDS— Session timeout: Auth tokens expire after (default 1 hour) of inactivity. After timeout, the client must send auth headers again. The transport session remains active.[](https://m8ven.ai/mcp/rokrokss-gitlab-mcp-btyu13)