CVE-2026-51994 Details
Description
mcp-remote versions 0.1.32 through 0.1.38 are vulnerable to Server-Side Request Forgery (SSRF) via the resource_metadata URL extracted from a remote MCP server's WWW-Authenticate header
A Server-Side Request Forgery (SSRF) vulnerability exists in mcp-remote versions 0.1.32 through 0.1.38. The issue arises when the resource_metadata URL is extracted from a remote MCP server's WWW-Authenticate header. This URL is fetched without proper validation, allowing an attacker-controlled server to direct requests to localhost services, private network addresses, or cloud metadata endpoints accessible from the user's machine.
Users are advised to update to mcp-remote version 0.1.39 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 24, 2026CISA-ADP
Assessed Sep 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/geelen/mcp-remote | [email protected] | Source CodeVendor |
| https://github.com/geelen/mcp-remote/security/advisories | [email protected] | AdvisoryVendor |
| https://github.com/playb0t/mcp-remote-oauth-security/blob/v1.0.1/advisories/F-01-resource-metadata-ssrf.md | [email protected] | AdvisoryExploitRemedy |
| https://github.com/playb0t/mcp-remote-oauth-security#readme | [email protected] | BundleTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| mcp-remote | >= 0.1.32, <= 0.1.38 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 25, 2026 | CVE Modified | CISA-ADP |
| Sep 24, 2026 | New CVE Received | [email protected] |
Volerion