← Back to search

CVE-2026-51996

9.8 CRITICALpublic exploit available

Published 2026-09-24 · Updated 2026-09-29

AI risk analysis

Summary
A remote code execution vulnerability exists in geelen mcp-remote versions 0.1.16 through 0.1.38, allowing attackers to execute arbitrary code via specific functions.
Exploitability
Exploitation is relatively straightforward given the public exploit references. Attackers need access to the affected function calls.
Blast radius
If exploited, this could lead to complete compromise of the affected system, including data theft, service disruption, and further lateral movement.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to geelen mcp-remote 0.1.39 or later.
rcewebarbitrary-code-execution

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the src/lib/utils.ts and the getServerUrlHash function

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-328

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.