
Upwind Security MDR@UpwindMDR
🚨Critical - mcp-remote RCE via getServerUrlHash Code Injection (CVE-2026-51996) geelen mcp-remote src/lib/utils.ts getServerUrlHash() is reachable remotely and allows attacker-controlled input to trigger code injection, leading to arbitrary code execution on the host. Instances not exposing the remote interface are not affected. 👉Affected: mcp-remote 0.1.16-0.1.38
0001059
309 followersView on X
