An issue in geelen mcp-remote 0.1.18 through 0.1.38 allows a remote attacker to obtain sensitive information via the SSE transport eventSourceInit fetch wrapper " src/lib/utils.ts
Published Sep 24, 2026
No CVSS score
EPSS 0.25%
Description
Affected products
Remediation
References (4)
Change history (0)
No recorded changes yet.