CYBER CODE RED

Get real-time updates on Telegram

Verified

CVE-2026-108716: mcp-remote 0.8.0 through 0.14.3

Affected technology

mcp-remote · 0.8.0 through 0.14.3
punkpeye

Description’s affected range: through 0.14.3

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · No privileges required · Passive user interaction

What an attacker can do

The source says when discovered device authorization and token endpoints are non-loopback http URLs, on-path network attackers can capture the client secret plus issued access and refresh tokens. Vendor/CNA’s CVSS 4.0 assessment (base score 6.0/10) rates confidentiality impact as high; integrity and availability impact as none.

Published

CWE
CWE-319
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-108716.html