PatchSiren

punkpeye CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM punkpeye CVE published 2026-10-11

CVE-2026-108716

CVE-2026-108716: The mcp-remote package, versions 0.8.0 through 0.14.3, contains a cleartext transmission vulnerability in the authorizeWithDeviceCode function. This function sends client secrets and receives tokens without enforcing HTTPS endpoints, allowing on-path network attackers to capture sensitive information when device authorization and token endpoints are non-loopback http URLs. Defenders respo [truncated]