CVE-2026-108716
Received Received - Intake

mcp-remote Cleartext Transmission of Client Secrets and Tokens

Vulnerability report for CVE-2026-108716, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

mcp-remote 0.8.0 through 0.14.3 contains a cleartext transmission vulnerability in authorizeWithDeviceCode that sends client secrets and receives tokens without enforcing HTTPS endpoints. When discovered device authorization and token endpoints are non-loopback http URLs, on-path network attackers can capture the client secret plus issued access and refresh tokens.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
punkpeye mcp-remote 0.8.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-319 The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a cleartext transmission issue in mcp-remote versions 0.8.0 through 0.14.3. It occurs in the authorizeWithDeviceCode function which uses the OAuth 2.0 Device Authorization Grant flow. When device authorization and token endpoints use non-loopback HTTP URLs instead of HTTPS, sensitive data like client secrets, access tokens, and refresh tokens are sent and received without encryption. This allows on-path network attackers to intercept this information.

Detection Guidance

Check if mcp-remote versions 0.8.0 through 0.14.3 are installed. Inspect network traffic for cleartext OAuth device authorization flows using tools like Wireshark or tcpdump. Look for HTTP requests to device authorization or token endpoints that transmit client secrets or tokens without HTTPS.

Impact Analysis

If you use mcp-remote with device code authentication and the authorization server endpoints are HTTP (not HTTPS or loopback), attackers on your network can capture your client secrets and tokens. This could lead to unauthorized access to your MCP server, data breaches, or account takeover. The impact includes loss of confidentiality for sensitive credentials and tokens.

Compliance Impact

This vulnerability likely violates compliance requirements for data protection standards like GDPR and HIPAA, which mandate encryption for transmission of sensitive data. Cleartext transmission of credentials and tokens could result in unauthorized access to personal or health information, leading to regulatory penalties and loss of trust.

Mitigation Strategies

Upgrade mcp-remote to a version beyond 0.14.3 where the vulnerability is fixed. Ensure all OAuth endpoints use HTTPS or loopback addresses. Review and update authorization server metadata to enforce HTTPS endpoints. Disable device code flow if not required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108716. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart