CVE-2026-51995

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An issue in geelen mcp-remote 0.1.32 through 0.1.38 allows a remote attacker to obtain sensitive information via the src/lib/authorization-server-metadata.ts, src/lib/utils.ts components

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-24: 109-24
Full discourse1 post
  • Upwind Security MDR@UpwindMDR

    🚨High - mcp-remote Authorization Server Metadata Info Leak (CVE-2026-51995) geelen mcp-remote leaks sensitive data via the authorization server metadata handling in src/lib/authorization-server-metadata.ts, with supporting parsing/utility logic in src/lib/utils.ts. A remote attacker can query/trigger metadata processing to expose internal configuration/values. Local-only deployments not exposing the metadata endpoint are not impacted. 👉Affected: geelen mcp-remote 0.1.32-0.1.38

    0000059
    305 followersView on X

Explore more