VYPR
Vendor

Geelen

Products
1
CVEs
5
Across products
5
Status
Private

Products

1

Recent CVEs

5
  • CVE-2025-6514CriJul 9, 2025
    risk 0.62cvss 9.6epss 0.78

    mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the authorization_endpoint response URL

  • CVE-2026-51995HigSep 24, 2026
    risk 0.49cvss 7.5epss —

    An issue in geelen mcp-remote 0.1.32 through 0.1.38 allows a remote attacker to obtain sensitive information via the src/lib/authorization-server-metadata.ts, src/lib/utils.ts components

  • CVE-2026-52001Sep 24, 2026
    risk 0.00cvss —epss —

    An issue in geelen mcp-remote 0.1.18 through 0.1.38 allows a remote attacker to obtain sensitive information via the SSE transport eventSourceInit fetch wrapper " src/lib/utils.ts

  • CVE-2026-51997Sep 24, 2026
    risk 0.00cvss —epss —

    An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the open() functions

  • CVE-2026-51996Sep 24, 2026
    risk 0.00cvss —epss —

    An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the src/lib/utils.ts and the getServerUrlHash function