PatchSiren

geelen CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH geelen CVE published 2026-09-24

CVE-2026-51997

A remote code execution vulnerability exists in geelen mcp-remote versions 0.1.16 through 0.1.38. This issue allows a remote attacker to execute arbitrary code via the open() functions. The CVSS score for this vulnerability is 8.8, indicating a high severity level. Defenders should assess exposure and prioritize patching or mitigation. The vulnerability is a result of the open() functions in mcp-remote, w [truncated]

CRITICAL geelen CVE published 2026-09-24

CVE-2026-51994

A critical vulnerability was found in mcp-remote versions 0.1.32 through 0.1.38, which are susceptible to Server-Side Request Forgery (SSRF) via the resource_metadata URL extracted from a remote MCP server's WWW-Authenticate header. This issue has a CVSS score of 9.1 and is considered critical. The vulnerability allows attackers to make unauthorized requests, potentially leading to significant operational [truncated]