MEDIUM
punkpeye
CVE published 2026-10-11
CVE-2026-108716
CVE-2026-108716: The mcp-remote package, versions 0.8.0 through 0.14.3, contains a cleartext transmission vulnerability in the authorizeWithDeviceCode function. This function sends client secrets and receives tokens without enforcing HTTPS endpoints, allowing on-path network attackers to capture sensitive information when device authorization and token endpoints are non-loopback http URLs. Defenders respo [truncated]