---
id: CVE-2026-52001
title: >-
  An issue in geelen mcp-remote 0.1.18 through 0.1.38 allows a remote attacker
  to obtain sensitive information via the SSE transport eventSourceInit fetch
  wrapper " src/lib/utils.ts
summary: >-
  An issue in geelen mcp-remote 0.1.18 through 0.1.38 allows a remote attacker
  to obtain sensitive information via the SSE transport eventSourceInit fetch
  wrapper " src/lib/utils.ts
severity: none
published: '2026-09-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T21:08:55.030'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-52001'
references:
  - url: 'https://github.com/geelen/mcp-remote'
    label: cve@mitre.org
  - url: 'https://github.com/geelen/mcp-remote/security/advisories'
    label: cve@mitre.org
  - url: 'https://github.com/playb0t/mcp-remote-oauth-security#readme'
    label: cve@mitre.org
  - url: >-
      https://github.com/playb0t/mcp-remote-oauth-security/blob/v1.0.1/advisories/F-11-sse-token-origin-scope.md
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-24T15:45:56.641Z'
---

## Overview

An issue in geelen mcp-remote 0.1.18 through 0.1.38 allows a remote attacker to obtain sensitive information via the SSE transport eventSourceInit fetch wrapper " src/lib/utils.ts

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
