Junglewise Threat Intelligence

CVE-2026-51994: mcp-remote versions 0.1.32 through 0.1.38 are vulnerable to Server-Side Request Forgery (SSRF) via the resource_metadata URL extracted from

CVE-2026-51994 · Severity: critical · CVSS 9.1 · Published 2026-09-24