PT-2026-97824 · Geelen · Mcp-Remote

CVE-2026-51996

·

Published

2026-09-24

·

Updated

2026-09-29

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions geelen mcp-remote versions 0.1.16 through 0.1.38
Description A code injection flaw exists in the getServerUrlHash() function within src/lib/utils.ts. This issue allows a remote attacker to execute arbitrary code on the host system by providing controlled input. This is only possible if the remote interface is exposed.
Recommendations Update geelen mcp-remote to a version newer than 0.1.38. As a temporary mitigation, disable the remote interface to prevent remote exploitation.

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-51996

Affected Products

Mcp-Remote