CVE-2026-51997
Received Received - Intake

Remote Code Execution in geelen mcp-remote

Vulnerability report for CVE-2026-51997, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-24

Last updated on: 2026-09-24

Assigner: MITRE

Description

An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the open() functions

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-24
Last Modified
2026-09-24
Generated
2026-09-24
AI Q&A
2026-09-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
geelen mcp-remote From 0.1.16 (inc) to 0.1.38 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-51997 is a vulnerability in geelen mcp-remote versions 0.1.16 through 0.1.38 where incomplete URL validation allows a remote attacker to execute arbitrary code via the open() functions. The issue involves improper handling of URLs, enabling attackers to open restricted or internal URLs in a user's browser.

Detection Guidance

Check if your system uses mcp-remote versions 0.1.16 through 0.1.38. Inspect browser launch behavior for improper URL handling. Look for unexpected browser navigation to internal or restricted URLs.

Impact Analysis

This vulnerability could allow an attacker to interact with internal services, perform reconnaissance, or facilitate browser-mediated CSRF attacks if the target service lacks protections. Attackers might exploit it to access sensitive internal resources or execute unauthorized actions on behalf of the user.

Mitigation Strategies

Upgrade mcp-remote to a version that includes proper URL validation. Explicitly reject loopback, private, link-local, multicast, reserved, and metadata-service addresses. Display the final origin to users before navigation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-51997. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart