CVE-2026-51994
NONE—CVSS v3
—CVSS v2
—
EPSS (exploit probability)
—CWE
Description
mcp-remote versions 0.1.32 through 0.1.38 are vulnerable to Server-Side Request Forgery (SSRF) via the resource_metadata URL extracted from a remote MCP server's WWW-Authenticate header
Affected routers (0)
No routers currently mapped to this CVE in our database.