Medium severity5.3NVD Advisory· Published Oct 11, 2026
CVE-2026-108716
CVE-2026-108716
Description
mcp-remote 0.8.0 through 0.14.3 contains a cleartext transmission vulnerability in authorizeWithDeviceCode that sends client secrets and receives tokens without enforcing HTTPS endpoints. When discovered device authorization and token endpoints are non-loopback http URLs, on-path network attackers can capture the client secret plus issued access and refresh tokens.
Affected products
1- Range: 0.8.0-0.14.3
Patches
Vulnerability mechanics
References
4- github.com/punkpeye/mcp-remote/blob/v0.14.3/src/lib/client-credentials.tsnvd
- github.com/punkpeye/mcp-remote/blob/v0.14.3/src/lib/device-authorization.tsnvd
- hackmd.io/@haind03/punkpeye-mcp-remote-device-code-cleartext-oauth-transportnvd
- www.vulncheck.com/advisories/mcp-remote-0.8.0-through-0.14.3-cleartext-credential-transmission-via-device-code-oauth-grantnvd
News mentions
0No linked articles in our index yet.