CVE-2025-6514

Published Jul 9, 2025

Last updated 5 months ago

CVSS critical 9.6
MCP
mcp-remote
Open source

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-6514 is a vulnerability in mcp-remote that can lead to arbitrary OS command execution when Model Context Protocol (MCP) clients connect to an untrusted MCP server. This is due to crafted input from the authorization\_endpoint response URL. The vulnerability affects mcp-remote versions 0.0.5 to 0.1.15 and has been fixed in version 0.1.16. The mcp-remote tool is used by applications like Claude Desktop, Cursor, and Windsurf to connect with remote MCP servers via HTTP transport by serving as a proxy. When a user configures their LLM host to connect to a remote MCP server, mcp-remote initiates communication with the MCP server and may be asked to authenticate. The server responds with its authorization\_endpoint URL, which, if crafted maliciously, can cause a command injection, allowing an attacker to execute arbitrary OS commands.

Description
mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the authorization_endpoint response URL
Source
reefs@jfrog.com
NVD status
Deferred

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.6
Impact score
6
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

reefs@jfrog.com
CWE-78

Social media

Hype score
Not currently trending
  1. Analysis of 3984 public AI agent skills shows 36.8% contain security issues and 13.4% are critical. Malicious skill.md files can exfiltrate credentials, establish persistence via ~/.@claudeai/CLAUDE.md, and survive reinstalls. Snyk’s ToxicSkills report and CVE-2025-6514 in

    @WorldCyberNewsX

    10 Sept 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2025-6514: a bug in the mcp-remote proxy (437k+ downloads) let a malicious MCP server run commands on any connecting client. RCE, rated 9.6. The MCP client and proxy are attack surface too, not just tool descriptions. Vet what you connect to, and sandbox it.

    @sundi133

    8 Sept 2026

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. TRC analysis reveals attackers exploiting CVE-2025-6514 in MCP servers to inject OS commands, then escalating privileges through plaintext credentials in config files. The credential sprawl across ungoverned MCP deployments enables rapid lateral movement once initial systems are

    @aviatrixtrc

    17 Aug 2026

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. PSA for anyone wiring MCP servers into agents: postmark-mcp and the mcp-remote RCE (CVE-2025-6514, ~500k installs) would both have passed a readiness check. Readiness ≠ safety. Read the source before you install. We track these incidents: https://t.co/jepzZXwwLo https://t.co

    @SRLsasame

    25 Jun 2026

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2025-6514 — 437,000+ dev environments compromised through a single MCP npm package. The attack path: crafted OAuth endpoint → shell injection → RCE with user privileges. Attackers got: env vars, credentials, internal repos. The attack surface isn't the AI model. It's

    @EdwardHans62753

    26 May 2026

    8 Impressions

    1 Retweet

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  6. When OAuth Becomes a Weapon: Lessons from CVE-2025-6514 #AIAgentSecurity #OAuthFlaw #CVE20256514 #TrustInversion #CapabilityBasedAuth https://t.co/Cgy2BjDX8u

    @reverseame

    17 Apr 2026

    450 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  7. CVE-2025-6514 — CVSS 9.6. RCE. If you use mcp-remote, a malicious server can hijack your OAuth flow, intercept tokens, and run arbitrary commands on your machine. Check your version NOW. Sentori flags this automatically: npx @nexylore/sentori scan #MCP #Security #OpenSourc

    @vmgsahm1

    9 Apr 2026

    180 Impressions

    0 Retweets

    2 Likes

    1 Bookmark

    3 Replies

    0 Quotes

  8. 43% of MCP implementations have command injection flaws. Critical CVEs like CVE-2025-6514 (CVSS 9.6) expose AI agents to RCE. Secure your agentic AI workflows with Abcas MCP Guard. https://t.co/R2jVo8VAGm #MCPsecurity #AISecurity

    @abcas_mcp_guard

    15 Mar 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. أداة MEDUSA لاختبار أمن التطبيقات أداة MEDUSA الجديدة، وهي أداة SAST تعتمد على الذكاء الاصطناعي، توفر 74 ماسحًا متخصصًا وأكثر من 180 قاعدة أمنية. تركز الأداة على تح

    @MisbarSec

    30 Jan 2026

    62 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. When OAuth Becomes a Weapon: Lessons from CVE-2025-6514 | Amla Labs https://t.co/YBZc3MCMeb

    @akaclandestine

    22 Dec 2025

    2568 Impressions

    3 Retweets

    25 Likes

    8 Bookmarks

    1 Reply

    0 Quotes

  11. When OAuth Becomes a Weapon: Lessons from CVE-2025-6514 https://t.co/GHK2ghEndO

    @securityshell

    22 Dec 2025

    4691 Impressions

    13 Retweets

    58 Likes

    48 Bookmarks

    0 Replies

    0 Quotes

  12. When OAuth Becomes a Weapon: Lessons from CVE-2025-6514 https://t.co/cu4URIdlCn https://t.co/tSPCol9klP

    @secharvesterx

    22 Dec 2025

    67 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. When OAuth Becomes a Weapon: Lessons from CVE-2025-6514 https://t.co/EHMIt0ZYae

    @_r_netsec

    22 Dec 2025

    1940 Impressions

    4 Retweets

    17 Likes

    11 Bookmarks

    1 Reply

    0 Quotes

  14. CVE-2025-6514 is a critical CVSS 9.6 vulnerability in mcp-remote that allows remote code execution when connecting to untrusted MCP servers. This is the first full RCE achieved in a real-world MCP client scenario. JFrog discovery: https://t.co/S5aCGxOiDK | MCP security: https://t

    @cyber_breach

    17 Dec 2025

    49 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. GitHub - Cyberency/CVE-2025-6514: mcp-remote exposed to OS command injection https://t.co/JyRMlP3QcX

    @akaclandestine

    26 Oct 2025

    1929 Impressions

    2 Retweets

    18 Likes

    6 Bookmarks

    0 Replies

    0 Quotes

  16. (1/5) 🚨 CVE-2025-6514: Critical RCE in mcp-remote (CVSS 9.6) JFrog Security disclosed a command injection vulnerability in mcp-remote (v0.0.5-0.1.15) that achieves RCE when connecting to malicious MCP servers. A thread 🧵: -

    @hackcubes

    22 Oct 2025

    24 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  17. https://t.co/T94EjyV1AY Vulnerability threatens LLM clients A security research team announces the discovery of a critical vulnerability in an MCP-remote server that allows remote code execution. The vulnerability, CVE-2025-6514 (CVSS score: 9,6), allows the execution of arbi

    @B2bCyber

    29 Sept 2025

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. MCP is powerful, but the security stakes are high. 🛡️ Prompt injection, tool poisoning, OAuth flaws (e.g. CVE-2025-6514), RCE risks. Case studies: SQLite MCP with SQL injection, Asana duped via multi-tenant exposure, Jira agents manipulated via prompts. Must-do’s: lea

    @DataScienceDojo

    17 Sept 2025

    2161 Impressions

    3 Retweets

    10 Likes

    2 Bookmarks

    1 Reply

    0 Quotes

  19. Selling #nday #exploit for CVE-2025-6514 (mcp-remote) <= 0.1.15! Contact marshallwhittaker@gmail.com or dm for details! #Hacking #CyberSec #hackingtool #infosec https://t.co/NEfoLh6Sst

    @oxagast

    24 Aug 2025

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. 🚨 A flaw in MCP-remote (CVE-2025-6514) has compromised 437K+ AI dev environments, turning into a massive #SoftwareSupplyChain attack. Learn how it happened and how to lock down your #AI workflows: https://t.co/IPLGUG2Ieh

    @jfrog

    14 Aug 2025

    94 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. 437,000+ downloads of a popular proxy. ⚠️ One malicious OAuth response. 💥 Your shell executes. Full RCE. This is CVE-2025-6514. 🧟‍♂️ MCP Horror Stories: Issue 2 breaks it down. Docker MCP shuts it down. 📖 Read it: https://t.co/Rmyfcn8LoG https://t.co/8VanUwB9

    @Docker

    7 Aug 2025

    34194 Impressions

    13 Retweets

    49 Likes

    12 Bookmarks

    4 Replies

    2 Quotes

  22. Vulnerabilidad crítica en mcp-remote (CVE-2025-6514, CVSS 9.6) permite ejecución remota de código, afectando 437,000+ descargas. Actualiza a v0.1.16 y usa servidores MCP confiables con HTTPS. #Ciberseguridad #MCP https://t.co/1ho0KMWyfl

    @taidynamics

    6 Aug 2025

    21 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  23. MCP adoption is surging—and July brought the first critical RCE in the toolchain: mcp-remote (CVE-2025-6514). If you connect to untrusted servers, you’re exposed. Update to 0.1.16. #MCP #AppSec #RCE https://t.co/B6Nc2ePKnn

    @DeepEngineerHub

    5 Aug 2025

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. Critical RCE Vulnerability in mcp-remote: CVE-2025-6514 Threatens LLM Clients https://t.co/J3SHk7qywt

    @_r_netsec

    17 Jul 2025

    1112 Impressions

    2 Retweets

    7 Likes

    5 Bookmarks

    1 Reply

    0 Quotes

  25. CVE-2025-6514: mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the authorization_endpoint response URL https://t.co/cufgwXpzlw

    @ZeroDayFacts

    16 Jul 2025

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. 𝗖𝗥𝗜𝗧𝗜𝗖𝗔𝗟 𝗔𝗟𝗘𝗥𝗧: 𝗺𝗰𝗽-𝗿𝗲𝗺𝗼𝘁𝗲 𝗩𝘂𝗹𝗻 𝗘𝘅𝗽𝗼𝘀𝗲𝘀 𝗟𝗟𝗠 𝗖𝗹𝗶𝗲𝗻𝘁𝘀 𝘁𝗼 𝗥𝗲𝗺𝗼𝘁𝗲 𝗖𝗼𝗱𝗲 𝗘𝘅𝗲𝗰𝘂𝘁𝗶𝗼𝗻 (𝗖𝗩

    @RootsOdin

    15 Jul 2025

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. Guess what? Like any tech, #MCP isn't immune to flaws. #CVE-2025-6514 affects NPM's mcp-remote MCP client library versions 0.5.0-0 through 0.1.15, allowing OS command injection via URL authentication when connecting to untrusted MCP servers – and yes, that means possible #RCE.

    @CheckmarxZero

    15 Jul 2025

    73 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. CVE-2025-6514 (CVSS:9.6, CRITICAL) is Awaiting Analysis. mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the aut..https://t.co/bHgpmcSVc7 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    14 Jul 2025

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. Critical RCE Vulnerability in mcp-remote: CVE-2025-6514 Threatens LLM Clients https://t.co/5bkdCatYZH #appsec

    @eyalestrin

    12 Jul 2025

    22 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. Warning: #CVE-2025-6514 (CVSS 9.6, CRITICAL) — #mcp-remote vulnerable to OS command injection via crafted input from malicious "authorization_endpoint" response. More info at: https://t.co/muUgDyjev2 #Patch #Patch #Patch

    @CCBalert

    11 Jul 2025

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  31. Critical mcp-remote Vulnerability Enables Remote Code Execution, Impacting 437,000+ Downloads Critical vulnerabilities have been found in tools using Anthropic’s Model Context Protocol (MCP), posing major security risks. CVE-2025-6514 (CVSS 9.6) affects the "mcp-remote proxy",

    @dCypherIO

    11 Jul 2025

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. محققان آسیب‌پذیری بحرانی در پروژه متن‌باز mcp-remote کشف کرده‌اند که می‌تواند منجر به اجرای دستورات دلخواه سیستم عامل شود. این آسیب‌پذیری با شناسه CVE-2025-6514

    @Teeegra

    11 Jul 2025

    565 Impressions

    0 Retweets

    13 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  33. CVE-2025-6514: Command Injection in mcp-remote Turns Client Connections into Attack Vectors https://t.co/OdHRVnQoMU

    @_cvereports

    11 Jul 2025

    17 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  34. Vulnerabilità critica CVE-2025-6514: rischio RCE per client MCP-Remote nel mondo AI Vulnerabilità, AI, attacchi RCE, mcp, mcp-remote, rce https://t.co/aXn1MZ1gIU https://t.co/3pfLdONJRT

    @matricedigitale

    11 Jul 2025

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  35. 10/07/2025 Critical mcp-remote vulnerability (CVE-2025-6514) enables RCE on 437,000+ systems! 🚨 With a CVSS score of 9.6, immediate patching is essential to mitigate risks. Source: https://t.co/TU1gLglnLv

    @kernyx64

    11 Jul 2025

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  36. A critical vulnerability in mcp-remote (CVE-2025-6514) affects versions up to 0.1.15, enabling remote code execution via malicious MCP servers. Over 437,000 downloads impacted; updates to 0.1.16 are recommended. ⚠️ #OpenSource #SecurityUK https://t.co/VELyMQ9o18

    @TweetThreatNews

    10 Jul 2025

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  37. Critical flaw CVE-2025-6514 in mcp-remote project poses high-risk vulnerability. Addressing it is crucial for system security. https://t.co/wA7PT5jGIR #Cybersecurity #InfoSec

    @threatlight

    10 Jul 2025

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  38. RCE Vulnerability in mcp-remote: CVE-2025-6514 Threatens LLM Clients - https://t.co/kD0IG34ft5 https://t.co/eHCZQOo8HW

    @AISecHub

    10 Jul 2025

    179 Impressions

    0 Retweets

    4 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  39. 🚨 Critical vulnerability (CVE-2025-6514) in mcp-remote enables FULL Remote Code Execution in LLM clients. The flaw affects Claude Desktop, Cursor & Windsurf apps connecting to untrusted MCP servers. First documented RCE case in MCP communications with CVSS score of 9.6.

    @threatcluster

    10 Jul 2025

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  40. Critical RCE Vulnerability in mcp-remote: CVE-2025-6514 Threatens LLM Clients https://t.co/YZFdcreQbh

    @Dinosn

    10 Jul 2025

    2235 Impressions

    5 Retweets

    11 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  41. Critical RCE Vulnerability in mcp-remote: CVE-2025-6514 Threatens LLM Clients https://t.co/J3SHk7qywt

    @_r_netsec

    9 Jul 2025

    1940 Impressions

    9 Retweets

    15 Likes

    7 Bookmarks

    0 Replies

    0 Quotes

  42. [CVE-2025-6514: CRITICAL] mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the authorization_endpoint response URL#cve,CVE-2025-6514,#cybersecurity https://t.co/fKvXNHlcRI https://t.co/nxcPrhXHR8

    @CveFindCom

    9 Jul 2025

    68 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes