Impact
The vulnerability allows a device authorization component to send client secrets and receive access tokens without enforcing HTTPS. The transmitted credentials and tokens are therefore exposed in cleartext and can be captured by an on‑path network attacker. The exposed information permits full impersonation of the client and continued use of any authorized resources. The weakness is classified under CWE‑319.
Affected Systems
Vendor punkpeye’s mcp‑remote product, versions 0.8.0 through 0.14.3, is affected. No specific sub‑product or build is excluded; the entire range of these releases shares the same insecure implementation.
Risk and Exploitability
The CVSS score of 6 indicates a severity vulnerability. No EPSS score is published, so the likelihood of exploitation is not quantified, and the issue is not listed in the CISA KEV catalog. An attacker with access to the network path that hosts the device‑authorization and token endpoints, provided they are non‑loopback HTTP URLs, can capture the client secret, access token, and refresh token. Remote attackers with such network access could therefore acquire the credentials to compromise the application’s authentication flow.
OpenCVE Enrichment