Sceawere
Vulnerability Detail
CVE-2026-108716UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
mcp-remote Cleartext Credential Exposure
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 4h ago
- Vendor
- punkpeye
- Product
- mcp-remote
- Attack Type
- Cleartext Transmission of Sensitive Information
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
mcp-remote 0.8.0 through 0.14.3 contains a cleartext transmission vulnerability in authorizeWithDeviceCode that sends client secrets and receives tokens without enforcing HTTPS endpoints. When discovered device authorization and token endpoints are non-loopback http URLs, on-path network attackers can capture the client secret plus issued access and refresh tokens.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-11T13:17:14.720Z",
"pubdate": "2026-10-11T13:17:14.720Z",
"executiveSummary": "The mcp-remote package, specifically versions 0.8.0 through 0.14.3, is susceptible to a cleartext transmission vulnerability within the authorizeWithDeviceCode function. This flaw arises from the library's failure to enforce mandatory HTTPS for device authorization and token exchange endpoints. Consequently, sensitive authentication data—including client secrets, access tokens, and refresh tokens—can be transmitted over unencrypted HTTP channels.\nAn on-path network attacker, such as one positioned on a local network or a compromised gateway, can conduct traffic interception to capture these credentials. By monitoring non-loopback network traffic, an adversary can perform man-in-the-middle (MitM) attacks to exfiltrate valid session tokens and application secrets. This vulnerability poses a severe risk to the confidentiality and integrity of authenticated sessions, potentially allowing an attacker to impersonate the client or maintain persistent unauthorized access to protected resources. The exploit requires the endpoint configuration to utilize insecure HTTP URLs, making it highly dependent on the service's network environment.",
"technicalDetails": "The vulnerability resides in the authorizeWithDeviceCode function of mcp-remote (versions 0.8.0 to 0.14.3). The core architectural flaw is the absence of transport layer security enforcement; the library fails to validate that the device authorization and token exchange endpoints utilize HTTPS. When the library is configured to interact with endpoints using HTTP URI schemes, it transmits sensitive authentication payloads in cleartext across the network.\nDuring the OAuth 2.0 Device Authorization Grant flow, the client performs an exchange with the Authorization Server to retrieve tokens. The vulnerable implementation sends the client_secret and subsequently receives the access_token and refresh_token without verifying the encryption status of the underlying transport layer. This behavior exposes the entire authentication exchange to packet sniffing and interception techniques.\nAn on-path attacker can exploit this by positioning themselves at any point between the client and the authorization server. Because the connection is not encrypted via TLS, the attacker can use standard network analysis tools (e.g., tcpdump, Wireshark, or MitMProxy) to capture the HTTP traffic. The attack flow proceeds as follows: 1) The attacker monitors network traffic for traffic directed at the configured authorization/token endpoints. 2) The attacker intercepts the HTTP POST request containing the client_secret or the HTTP response containing the access and refresh tokens. 3) The attacker parses the raw data packets to extract the credential information. 4) The attacker uses the exfiltrated tokens to authenticate as the client, gaining unauthorized access to the client's resources.\nThe scope of this vulnerability extends to any environment where mcp-remote is used to initiate flows against endpoints that are not strictly limited to loopback or HTTPS interfaces. Since the client secret is transmitted in cleartext, the impact is comprehensive, as the secret can be reused to further impersonate the application until revoked. Furthermore, the theft of refresh tokens provides the adversary with the ability to maintain long-term access, circumventing short-lived access token expiration policies. There are no authentication or privilege requirements for the attacker, as they operate at the network layer to intercept traffic, making this a critical vulnerability for applications handling sensitive integrations."
}