---
id: CVE-2026-51996
title: >-
  An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker
  to execute arbitrary code via the src/lib/utils.ts and the getServerUrlHash
  function
summary: >-
  An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker
  to execute arbitrary code via the src/lib/utils.ts and the getServerUrlHash
  function
severity: none
published: '2026-09-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T21:08:55.030'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-51996'
references:
  - url: 'https://github.com/geelen/mcp-remote'
    label: cve@mitre.org
  - url: 'https://github.com/geelen/mcp-remote/security/advisories'
    label: cve@mitre.org
  - url: >-
      https://github.com/playb0t/mcp-remote-oauth-security/blob/v1.0.1/advisories/F-04-md5-token-isolation.md
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-24T15:45:56.640Z'
epss: 0.00289
epssPercentile: 0.19136
---

## Overview

An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the src/lib/utils.ts and the getServerUrlHash function

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
