A remote code execution vulnerability exists in geelen mcp-remote versions 0.1.16 through 0.1.38. This issue allows a remote attacker to execute arbitrary code via the open() functions. The CVSS score for this vulnerability is 8.8, indicating a high severity level. Defenders should assess exposure and prioritize patching or mitigation. The vulnerability is a result of the open() functions in mcp-remote, w [truncated]
A critical vulnerability was found in mcp-remote versions 0.1.32 through 0.1.38, which are susceptible to Server-Side Request Forgery (SSRF) via the resource_metadata URL extracted from a remote MCP server's WWW-Authenticate header. This issue has a CVSS score of 9.1 and is considered critical. The vulnerability allows attackers to make unauthorized requests, potentially leading to significant operational [truncated]