Vulnerability  ·  2026-09-25

geelen mcp-remote: OAuth MCP proxy cluster - token-derivation hash RCE, open() arbitrary-code execution, SSRF via WWW-Authenticate resource_metadata, SSE token leak (CVE-2026-51994/51995/51996/51997/52001)

VulnerabilityHigh impactGlobalCVE-2026-51996
NVD published 2026-09-24 a cluster of flaws in geelen mcp-remote (the widely used OAuth proxy that lets local MCP clients connect to remote authenticated MCP servers), versions 0.1.16-0.1.38: arbitrary code execution via getServerUrlHash in src/lib/utils.ts (CVE-2026-51996) and via the open() functions (CVE-2026-51997), SSRF via the resource_metadata URL taken from a remote MCP server's WWW-Authenticate header (CVE-2026-51994), sensitive-information disclosure (CVE-2026-51995), and SSE transport eventSourceInit fetch-wrapper token leak (CVE-2026-52001). References point to playb0t MCP OAuth security advisories.
mcp-remote is the standard bridge for exposing remote OAuth-protected MCP servers to local agents; flaws that yield RCE or credential/token leakage in this bridge mean a malicious or compromised remote MCP server can execute code on or steal OAuth tokens from the developer/agent machine that connects to it - a supply-chain-adjacent agentic surface.
Connecting to a malicious remote MCP server (OAuth-protected) triggers token-derivation hashing/open() URL handling/SSE wrapper or WWW-Authenticate metadata paths, leading to code execution or token/credential leakage on the local machine.
geelen mcp-remote 0.1.16-0.1.38 (npm package)
Upgrade mcp-remote beyond 0.1.38; only connect to trusted remote MCP servers; review playb0t advisories for per-fix versions.
NVD CVE-2026-51996NVD CVE-2026-51994playb0t/mcp-remote-oauth-security advisories
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →