Description
mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the authorization_endpoint response URL
Problem types
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
0.0.5 (semver)
References
research.jfrog.com/...and-injection-rce-jfsa-2025-001290844/
github.com/...ommit/607b226a356cb61a239ffaba2fb3db1c9dea4bac
jfrog.com/...2025-6514-critical-mcp-remote-rce-vulnerability