Junglewise Threat Intelligence

CVE-2026-51995: geelen mcp-remote information disclosure in authorization

CVE-2026-51995 · Severity: high · CVSS 7.5 · Published 2026-09-24

Technologies: Geelen Mcp-Remote. Vendors: Geelen.

Executive brief

mcp-remote is a tool that allows MCP clients to connect to remote MCP servers with authentication support. A vulnerability in versions 0.1.32 through 0.1.38 allows remote attackers to obtain sensitive information through flaws in the authorization server metadata and utility components, potentially exposing authentication credentials or configuration data.

Technical details

An information disclosure vulnerability exists in the authorization-server-metadata.ts and utils.ts components of mcp-remote. The flaw allows remote network-based attackers to access sensitive information without requiring authentication. The vulnerability affects a critical authorization pathway, potentially exposing secrets or metadata that should remain protected.

Affected products

  • geelen mcp-remote 0.1.32 through 0.1.38

Timeline

  • 2026-09-24: disclosed

References

Related threats