
🚨High - mcp-remote Authorization Server Metadata Info Leak (CVE-2026-51995) geelen mcp-remote leaks sensitive data via the authorization server metadata handling in src/lib/authorization-server-metadata.ts, with supporting parsing/utility logic in src/lib/utils.ts. A remote attacker can query/trigger metadata processing to expose internal configuration/values. Local-only deployments not exposing the metadata endpoint are not impacted. 👉Affected: geelen mcp-remote 0.1.32-0.1.38
