Home

Description

mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the authorization_endpoint response URL

PUBLISHED Reserved 2025-06-23 | Published 2025-07-09 | Updated 2025-07-09 | Assigner JFROG




CRITICAL: 9.6CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Problem types

CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Product status

Default status
unaffected

0.0.5 (semver)
affected

References

research.jfrog.com/...and-injection-rce-jfsa-2025-001290844/ third-party-advisory

github.com/...ommit/607b226a356cb61a239ffaba2fb3db1c9dea4bac patch

jfrog.com/...2025-6514-critical-mcp-remote-rce-vulnerability technical-description

cve.org (CVE-2025-6514)

nvd.nist.gov (CVE-2025-6514)

Download JSON