Skip to content

Vulnerabilities

Vulnerabilities are the records GitLab keeps of what its security scanners found, tracked across pipelines. These actions list a project’s vulnerabilities with filters, read one, triage it (confirm, dismiss, resolve, or revert it to detected), count a project’s vulnerabilities by severity, and summarize the security reports of one pipeline. What a single pipeline’s scanners reported is on Security findings.

  • “List the critical vulnerabilities of project 42”
  • “Dismiss vulnerability 42 as a false positive”
  • “How many vulnerabilities does project 42 have by severity?”
  • “Which scanners ran in pipeline 123?”
  • Dynamic, the default surface: call gitlab_execute_action with action set to the action’s ID, such as vulnerability.confirm, and its parameters in params. gitlab_find_action finds an ID from a description of the task.
  • Meta (GITLAB_MCP_TOOL_SURFACE=meta): call gitlab_vulnerability with action set to the action’s name, such as confirm, and its parameters in params.
  • Individual (GITLAB_MCP_TOOL_SURFACE=individual): call the action’s own tool, such as gitlab_confirm_vulnerability, with its parameters as the arguments.

How many of these actions an instance serves at each tier, out of a total of 8:

  • Free: 0
  • Premium: 0
  • Ultimate: 8

Read-only actions: 4 of 8, the ones a deployment in read-only mode keeps.

The description of each action, and of each of its parameters, is the text the server serves for it on the default surface, quoted as served.

ActionIndividual
vulnerability.confirmgitlab_confirm_vulnerability
vulnerability.dismissgitlab_dismiss_vulnerability
vulnerability.getgitlab_get_vulnerability
vulnerability.listgitlab_list_vulnerabilities
vulnerability.pipeline_security_summarygitlab_pipeline_security_summary
vulnerability.resolvegitlab_resolve_vulnerability
vulnerability.revertgitlab_revert_vulnerability
vulnerability.severity_countgitlab_vulnerability_severity_count

Confirm a vulnerability as a real finding. Returns: the updated vulnerability with its new confirmed state and timestamp. See also: vulnerability.get, vulnerability.dismiss, vulnerability.resolve.

  • Meta-tool: gitlab_vulnerability, action confirm
  • Individual tool: gitlab_confirm_vulnerability
  • Tier: Ultimate
  • Behavior: writes, idempotent
ParameterTypeMandatoryDescription
idstringyesVulnerability GID (e.g. gid://gitlab/Vulnerability/42)

Dismiss a vulnerability with a dismissal reason. Returns: the updated vulnerability with its new dismissed state and timestamp. See also: vulnerability.get, vulnerability.confirm, vulnerability.revert.

  • Meta-tool: gitlab_vulnerability, action dismiss
  • Individual tool: gitlab_dismiss_vulnerability
  • Tier: Ultimate
  • Behavior: writes, idempotent
ParameterTypeMandatoryDescription
idstringyesVulnerability GID (e.g. gid://gitlab/Vulnerability/42)
commentstringnoReason for dismissal
dismissal_reasonstring (ACCEPTABLE_RISK, FALSE_POSITIVE, MITIGATING_CONTROL, NOT_APPLICABLE, USED_IN_TESTS)noDismissal reason: ACCEPTABLE_RISK, FALSE_POSITIVE, MITIGATING_CONTROL, USED_IN_TESTS, NOT_APPLICABLE

Get a single vulnerability by global ID. Returns: title, description, severity, state and its comment, report type, scanner, identifiers, CVSS assessments, EPSS and known-exploit data, location, solution, report links, a leaked token’s status, who confirmed, dismissed or resolved it, linked issues, and merge request. See also: vulnerability.list, vulnerability.dismiss, vulnerability.confirm.

  • Meta-tool: gitlab_vulnerability, action get
  • Individual tool: gitlab_get_vulnerability
  • Tier: Ultimate
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
idstringyesVulnerability GID (e.g. gid://gitlab/Vulnerability/42)

List a project’s vulnerabilities with severity, state, scanner, and report-type filters plus keyset pagination. Returns: matching vulnerabilities with UUID, title, severity, state, report type, scanner, identifiers, location, CVSS and EPSS data, who confirmed, dismissed or resolved each, detection time, and web URL. See also: vulnerability.get, vulnerability.severity_count, security_finding.list.

  • Meta-tool: gitlab_vulnerability, action list
  • Individual tool: gitlab_list_vulnerabilities
  • Tier: Ultimate
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
project_pathstringyesFull path of the project (e.g. my-group/my-project)
afterstringnoCursor for forward pagination (from previous response end_cursor)
beforestringnoCursor for backward pagination (from previous response start_cursor). The page size comes from last, or from first when last is omitted
firstintegernoNumber of items to return (default 20, max 100)
has_issuesbooleannoFilter by whether a linked issue exists
has_resolutionbooleannoFilter by whether a resolution exists
lastintegernoNumber of items to return from the end of the range (backward pagination). Cannot be combined with first
report_typestring[]noFilter by report type: SAST, DAST, DEPENDENCY_SCANNING, CONTAINER_SCANNING, CONTAINER_SCANNING_FOR_REGISTRY, SECRET_DETECTION, COVERAGE_FUZZING, API_FUZZING, CLUSTER_IMAGE_SCANNING, SARIF, GENERIC
scannerstring[]noFilter by scanner external IDs
severitystring[]noFilter by severity: CRITICAL, HIGH, MEDIUM, LOW, INFO, UNKNOWN
sortstring (severity_desc, severity_asc, detected_desc, detected_asc)noSort order: severity_desc, severity_asc, detected_desc, detected_asc
statestring[]noFilter by state: DETECTED, CONFIRMED, DISMISSED, RESOLVED

Summarize a pipeline’s security scan results. Returns: per-scanner vulnerability and scanned-resource counts for the pipeline (SAST, DAST, and other report types), the scans that ran with their status, errors and warnings, and the first resources a DAST scan requested. See also: vulnerability.severity_count, vulnerability.list.

  • Meta-tool: gitlab_vulnerability, action pipeline_security_summary
  • Individual tool: gitlab_pipeline_security_summary
  • Tier: Ultimate
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
pipeline_iidstringyesPipeline IID (internal ID within the project)
project_pathstringyesFull path of the project (e.g. my-group/my-project)

Resolve a vulnerability after it is fixed. Returns: the updated vulnerability with its new resolved state and timestamp. See also: vulnerability.get, vulnerability.confirm, vulnerability.revert.

  • Meta-tool: gitlab_vulnerability, action resolve
  • Individual tool: gitlab_resolve_vulnerability
  • Tier: Ultimate
  • Behavior: writes, idempotent
ParameterTypeMandatoryDescription
idstringyesVulnerability GID (e.g. gid://gitlab/Vulnerability/42)

Revert a vulnerability back to the detected state. Returns: the updated vulnerability with its restored detected state. See also: vulnerability.get, vulnerability.dismiss, vulnerability.resolve.

  • Meta-tool: gitlab_vulnerability, action revert
  • Individual tool: gitlab_revert_vulnerability
  • Tier: Ultimate
  • Behavior: writes, idempotent
ParameterTypeMandatoryDescription
idstringyesVulnerability GID (e.g. gid://gitlab/Vulnerability/42)

Count a project’s vulnerabilities grouped by severity. Returns: critical, high, medium, low, info, and unknown counts. See also: vulnerability.list, vulnerability.pipeline_security_summary.

  • Meta-tool: gitlab_vulnerability, action severity_count
  • Individual tool: gitlab_vulnerability_severity_count
  • Tier: Ultimate
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
project_pathstringyesFull path of the project (e.g. my-group/my-project)