CVE-2026-52001 Details
Description
An issue in geelen mcp-remote 0.1.18 through 0.1.38 allows a remote attacker to obtain sensitive information via the SSE transport eventSourceInit fetch wrapper " src/lib/utils.ts
A vulnerability exists in Geelen MCP-Remote versions 0.1.18 through 0.1.38, where the Server-Sent Events (SSE) transport wrapper does not properly validate the origin of the SSE endpoint before adding authorization tokens to requests. This oversight could potentially be exploited to forward tokens to unintended destinations, especially if the endpoint is on a different origin.
Users can update to Geelen MCP-Remote version 0.1.39 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/geelen/mcp-remote | [email protected] | Source CodeVendor |
| https://github.com/geelen/mcp-remote/security/advisories | [email protected] | AdvisoryVendor |
| https://github.com/playb0t/mcp-remote-oauth-security/blob/v1.0.1/advisories/F-11-sse-token-origin-scope.md | [email protected] | AdvisoryTechnical Analysis |
| https://github.com/playb0t/mcp-remote-oauth-security#readme | [email protected] | BundleTechnical Analysis |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| geelen mcp-remote | >= 0.1.18, <= 0.1.38 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 24, 2026 | New CVE Received | [email protected] |
Volerion