Executive brief
An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the open() functions
Junglewise Threat Intelligence
CVE-2026-51997 · Severity: high · CVSS 8.8 · Published 2026-09-24
An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the open() functions