GHSA-mvq8-g2rm-4rhmCriticalCVSS 9.8

An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary...

Published
September 24, 2026
Last Modified
September 29, 2026

🔗 CVE IDs covered (1)

📋 Description

An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the src/lib/utils.ts and the getServerUrlHash function

🔗 References (5)