VYPR
Vendor

Playb0t

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2026-52001Sep 24, 2026
    risk 0.00cvss —epss —

    An issue in geelen mcp-remote 0.1.18 through 0.1.38 allows a remote attacker to obtain sensitive information via the SSE transport eventSourceInit fetch wrapper " src/lib/utils.ts

  • CVE-2026-51996Sep 24, 2026
    risk 0.00cvss —epss —

    An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the src/lib/utils.ts and the getServerUrlHash function

  • CVE-2026-51994Sep 24, 2026
    risk 0.00cvss —epss —

    mcp-remote versions 0.1.32 through 0.1.38 are vulnerable to Server-Side Request Forgery (SSRF) via the resource_metadata URL extracted from a remote MCP server's WWW-Authenticate header