An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary...

zetlyn/cve-ghsa vulnerability ghsa GHSA-mvq8-g2rm-4rhm cve CVE-2026-51996 known 2026-09-24

https://github.com/advisories/GHSA-mvq8-g2rm-4rhm

Properties

cvss9.8
receipt
Source
GitHub advisories
Its words
9.8
Read by
field:cvss.score
Said since
2026-09-29 09:48 UTC
Last answered
2026-10-06 13:46 UTC
Original
open at the source
2026-09-29 09:48 UTC9.8
2026-09-28 11:44 UTC—
What the source handed over
{
  "credits": [],
  "cve_id": "CVE-2026-51996",
  "cvss": {
    "score": 9.8,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 9.8,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
    },
    "cvss_v4": {
      "score": 0.0,
      "vector_string": null
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-94",
      "name": "Improper Control of Generation of Code ('Code Injection')"
    }
  ],
  "description": "An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the src/lib/utils.ts and the getServerUrlHash function",
  "epss": {
    "percentage": 0.00289,
    "percentile": 0.19136
  },
  "ghsa_id": "GHSA-mvq8-g2rm-4rhm",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-mvq8-g2rm-4rhm",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-mvq8-g2rm-4rhm"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-51996"
    }
  ],
  "nvd_published_at": "2026-09-24T15:17:23Z",
  "published_at": "2026-09-24T15:31:34Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-51996",
    "https://github.com/geelen/mcp-remote",
    "https://github.com/geelen/mcp-remote/security/advisories",
    "https://github.com/playb0t/mcp-remote-oauth-security/blob/v1.0.1/advisories/F-04-md5-token-isolation.md",
    "https://github.com/advisories/GHSA-mvq8-g2rm-4rhm"
  ],
  "repository_advisory_url": null,
  "severity": "critical",
  "source_code_location": "",
  "summary": "An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary...",
  "type": "unreviewed",
  "updated_at": "2026-09-29T03:30:38Z",
  "url": "https://api.github.com/advisories/GHSA-mvq8-g2rm-4rhm",
  "vulnerabilities": [],
  "withdrawn_at": null
}
cweCWE-94
receipt
Source
GitHub advisories
Its words
CWE-94
Read by
field:cwes[].cwe_id
Said since
2026-09-29 09:48 UTC
Last answered
2026-10-06 13:46 UTC
Original
open at the source
2026-09-29 09:48 UTCCWE-94
2026-09-28 11:44 UTC—
What the source handed over
{
  "credits": [],
  "cve_id": "CVE-2026-51996",
  "cvss": {
    "score": 9.8,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 9.8,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
    },
    "cvss_v4": {
      "score": 0.0,
      "vector_string": null
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-94",
      "name": "Improper Control of Generation of Code ('Code Injection')"
    }
  ],
  "description": "An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the src/lib/utils.ts and the getServerUrlHash function",
  "epss": {
    "percentage": 0.00289,
    "percentile": 0.19136
  },
  "ghsa_id": "GHSA-mvq8-g2rm-4rhm",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-mvq8-g2rm-4rhm",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-mvq8-g2rm-4rhm"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-51996"
    }
  ],
  "nvd_published_at": "2026-09-24T15:17:23Z",
  "published_at": "2026-09-24T15:31:34Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-51996",
    "https://github.com/geelen/mcp-remote",
    "https://github.com/geelen/mcp-remote/security/advisories",
    "https://github.com/playb0t/mcp-remote-oauth-security/blob/v1.0.1/advisories/F-04-md5-token-isolation.md",
    "https://github.com/advisories/GHSA-mvq8-g2rm-4rhm"
  ],
  "repository_advisory_url": null,
  "severity": "critical",
  "source_code_location": "",
  "summary": "An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary...",
  "type": "unreviewed",
  "updated_at": "2026-09-29T03:30:38Z",
  "url": "https://api.github.com/advisories/GHSA-mvq8-g2rm-4rhm",
  "vulnerabilities": [],
  "withdrawn_at": null
}
severitycritical
GitHub's own rating, from the CVSS base score at 9.0 and above.
receipt
Source
GitHub advisories
Its words
critical
Read by
field:severity
Said since
2026-09-29 09:48 UTC
Last answered
2026-10-06 13:46 UTC
Original
open at the source
2026-09-29 09:48 UTCcritical
2026-09-28 11:44 UTCunknown
What the source handed over
{
  "credits": [],
  "cve_id": "CVE-2026-51996",
  "cvss": {
    "score": 9.8,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 9.8,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
    },
    "cvss_v4": {
      "score": 0.0,
      "vector_string": null
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-94",
      "name": "Improper Control of Generation of Code ('Code Injection')"
    }
  ],
  "description": "An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the src/lib/utils.ts and the getServerUrlHash function",
  "epss": {
    "percentage": 0.00289,
    "percentile": 0.19136
  },
  "ghsa_id": "GHSA-mvq8-g2rm-4rhm",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-mvq8-g2rm-4rhm",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-mvq8-g2rm-4rhm"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-51996"
    }
  ],
  "nvd_published_at": "2026-09-24T15:17:23Z",
  "published_at": "2026-09-24T15:31:34Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-51996",
    "https://github.com/geelen/mcp-remote",
    "https://github.com/geelen/mcp-remote/security/advisories",
    "https://github.com/playb0t/mcp-remote-oauth-security/blob/v1.0.1/advisories/F-04-md5-token-isolation.md",
    "https://github.com/advisories/GHSA-mvq8-g2rm-4rhm"
  ],
  "repository_advisory_url": null,
  "severity": "critical",
  "source_code_location": "",
  "summary": "An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary...",
  "type": "unreviewed",
  "updated_at": "2026-09-29T03:30:38Z",
  "url": "https://api.github.com/advisories/GHSA-mvq8-g2rm-4rhm",
  "vulnerabilities": [],
  "withdrawn_at": null
}

Text

An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary... An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the src/lib/utils.ts and the getServerUrlHash function