We are rushing to connect our AI agents to everything. The Model Context Protocol (MCP) is the glue making that happen, letting local clients talk to remote servers. But when we bridge these environments across networks, we keep forgetting a basic rule: remote metadata is not passive data.
If you use mcp-remote to bridge your local clients to remote MCP servers, you need to check your version. A recent security review of the tool through release 0.1.38 uncovered a cluster of vulnerabilities that turn routine protocol discovery into a massive liability.[1]
The worst of the bunch is CVE-2026-51994, a Critical 9.1 Server-Side Request Forgery (SSRF) flaw.[4] It abuses the OAuth discovery process. If you connect to an attacker-controlled MCP server, that server can return a 401 response with a crafted WWW-Authenticate header.[2] Embedded in that header is a resource_metadata URL.
The client takes that URL and blindly fetches it. It does not enforce an explicit protocol, nor does it block loopback or private network addresses.[2] The remote server can essentially use the developer’s machine as a pivot to hit internal services, local development ports, or cloud metadata endpoints.
The practitioner angle here is what really caught my attention. A PSA on Reddit pointed out that standard dependency scanners are likely missing these five CVEs for anyone running versions 0.1.16 through 0.1.38.[3] Because tools like mcp-remote are often installed globally or run as standalone bridges outside a specific project’s package manifest, your regular CI/CD pipeline scans won’t flag them.
We treat these bridges as dumb pipes, assuming the only risk is the data we explicitly ask the agent to process. But every URL, redirect, origin, and credential handoff during that initial handshake is a trust decision.[1]
Check your globally installed packages. If you are going to let an agent talk to a remote server, enforce outbound destination policies on the bridge itself, or run it in a container that has no route to your sensitive local services.
Sources
[1] https://github.com/playb0t/mcp-remote-oauth-security [2] https://github.com/playb0t/mcp-remote-oauth-security/blob/v1.0.1/advisories/F-01-resource-metadata-ssrf.md [3] https://www.reddit.com/r/cybersecurity/comments/1wyqza6/psa_if_you_run_mcpremote_01160138_your_dependency [4] https://nvd.nist.gov/vuln/detail/CVE-2026-51994