Cleartext Transmission Vulnerability in mcp-remote by PunkPye
CVE-2026-108716

6MEDIUM

Key Information:

Vendor

Punkpeye

Vendor
CVE Published:
11 October 2026

What is CVE-2026-108716?

The mcp-remote application versions 0.8.0 through 0.14.3 exhibit a vulnerability in the authorizeWithDeviceCode function, which allows cleartext transmission of sensitive data including client secrets and access tokens. This issue arises when device authorization and token endpoints are invoked using non-loopback HTTP URLs, making them susceptible to interception by on-path network attackers. The absence of HTTPS enforcement permits attackers to easily capture the credentials and tokens, posing a significant risk to users relying on secure token exchange.

Affected Version(s)

mcp-remote 0.8.0 <= 0.14.3

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HaiND from the Post and Telecommunication Institute of Technology
.