We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the authorization_endpoint response URL
Reserved 2025-06-23 | Published 2025-07-09 | Updated 2025-07-09 | Assigner JFROGCWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
research.jfrog.com/...and-injection-rce-jfsa-2025-001290844/
github.com/...ommit/607b226a356cb61a239ffaba2fb3db1c9dea4bac
jfrog.com/...2025-6514-critical-mcp-remote-rce-vulnerability
Support options