OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-51996

CRITICAL · CVSS 9.8 EPSS 0.47% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The geelen mcp-remote versions 0.1.16 through 0.1.38 are vulnerable to remote code execution due to a flaw in the getServerUrlHash function within the src/lib/utils.ts file. This vulnerability allows attackers to execute arbitrary code on affected systems, posing a significant risk to the integrity and security of the application. Organizations using these specific versions should prioritize remediation to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-51996
Severity
CRITICAL
CVSS
9.8
EPSS
0.47%

Original NVD Description

An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the src/lib/utils.ts and the getServerUrlHash function