CVE-2025-6514
Published Jul 9, 2025
Last updated 5 months ago
AI description
CVE-2025-6514 is a vulnerability in mcp-remote that can lead to arbitrary OS command execution when Model Context Protocol (MCP) clients connect to an untrusted MCP server. This is due to crafted input from the authorization\_endpoint response URL. The vulnerability affects mcp-remote versions 0.0.5 to 0.1.15 and has been fixed in version 0.1.16. The mcp-remote tool is used by applications like Claude Desktop, Cursor, and Windsurf to connect with remote MCP servers via HTTP transport by serving as a proxy. When a user configures their LLM host to connect to a remote MCP server, mcp-remote initiates communication with the MCP server and may be asked to authenticate. The server responds with its authorization\_endpoint URL, which, if crafted maliciously, can cause a command injection, allowing an attacker to execute arbitrary OS commands.
- Description
- mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the authorization_endpoint response URL
- Source
- reefs@jfrog.com
- NVD status
- Deferred
CVSS 3.1
- Type
- Secondary
- Base score
- 9.6
- Impact score
- 6
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
- reefs@jfrog.com
- CWE-78
- Hype score
- Not currently trending
Analysis of 3984 public AI agent skills shows 36.8% contain security issues and 13.4% are critical. Malicious skill.md files can exfiltrate credentials, establish persistence via ~/.@claudeai/CLAUDE.md, and survive reinstalls. Snyk’s ToxicSkills report and CVE-2025-6514 in
@WorldCyberNewsX
10 Sept 2026
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-6514: a bug in the mcp-remote proxy (437k+ downloads) let a malicious MCP server run commands on any connecting client. RCE, rated 9.6. The MCP client and proxy are attack surface too, not just tool descriptions. Vet what you connect to, and sandbox it.
@sundi133
8 Sept 2026
31 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
TRC analysis reveals attackers exploiting CVE-2025-6514 in MCP servers to inject OS commands, then escalating privileges through plaintext credentials in config files. The credential sprawl across ungoverned MCP deployments enables rapid lateral movement once initial systems are
@aviatrixtrc
17 Aug 2026
44 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
PSA for anyone wiring MCP servers into agents: postmark-mcp and the mcp-remote RCE (CVE-2025-6514, ~500k installs) would both have passed a readiness check. Readiness ≠ safety. Read the source before you install. We track these incidents: https://t.co/jepzZXwwLo https://t.co
@SRLsasame
25 Jun 2026
50 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-6514 — 437,000+ dev environments compromised through a single MCP npm package. The attack path: crafted OAuth endpoint → shell injection → RCE with user privileges. Attackers got: env vars, credentials, internal repos. The attack surface isn't the AI model. It's
@EdwardHans62753
26 May 2026
8 Impressions
1 Retweet
1 Like
1 Bookmark
0 Replies
0 Quotes
When OAuth Becomes a Weapon: Lessons from CVE-2025-6514 #AIAgentSecurity #OAuthFlaw #CVE20256514 #TrustInversion #CapabilityBasedAuth https://t.co/Cgy2BjDX8u
@reverseame
17 Apr 2026
450 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
CVE-2025-6514 — CVSS 9.6. RCE. If you use mcp-remote, a malicious server can hijack your OAuth flow, intercept tokens, and run arbitrary commands on your machine. Check your version NOW. Sentori flags this automatically: npx @nexylore/sentori scan #MCP #Security #OpenSourc
@vmgsahm1
9 Apr 2026
180 Impressions
0 Retweets
2 Likes
1 Bookmark
3 Replies
0 Quotes
43% of MCP implementations have command injection flaws. Critical CVEs like CVE-2025-6514 (CVSS 9.6) expose AI agents to RCE. Secure your agentic AI workflows with Abcas MCP Guard. https://t.co/R2jVo8VAGm #MCPsecurity #AISecurity
@abcas_mcp_guard
15 Mar 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
أداة MEDUSA لاختبار أمن التطبيقات أداة MEDUSA الجديدة، وهي أداة SAST تعتمد على الذكاء الاصطناعي، توفر 74 ماسحًا متخصصًا وأكثر من 180 قاعدة أمنية. تركز الأداة على تح
@MisbarSec
30 Jan 2026
62 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
When OAuth Becomes a Weapon: Lessons from CVE-2025-6514 | Amla Labs https://t.co/YBZc3MCMeb
@akaclandestine
22 Dec 2025
2568 Impressions
3 Retweets
25 Likes
8 Bookmarks
1 Reply
0 Quotes
When OAuth Becomes a Weapon: Lessons from CVE-2025-6514 https://t.co/GHK2ghEndO
@securityshell
22 Dec 2025
4691 Impressions
13 Retweets
58 Likes
48 Bookmarks
0 Replies
0 Quotes
When OAuth Becomes a Weapon: Lessons from CVE-2025-6514 https://t.co/cu4URIdlCn https://t.co/tSPCol9klP
@secharvesterx
22 Dec 2025
67 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
When OAuth Becomes a Weapon: Lessons from CVE-2025-6514 https://t.co/EHMIt0ZYae
@_r_netsec
22 Dec 2025
1940 Impressions
4 Retweets
17 Likes
11 Bookmarks
1 Reply
0 Quotes
CVE-2025-6514 is a critical CVSS 9.6 vulnerability in mcp-remote that allows remote code execution when connecting to untrusted MCP servers. This is the first full RCE achieved in a real-world MCP client scenario. JFrog discovery: https://t.co/S5aCGxOiDK | MCP security: https://t
@cyber_breach
17 Dec 2025
49 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
GitHub - Cyberency/CVE-2025-6514: mcp-remote exposed to OS command injection https://t.co/JyRMlP3QcX
@akaclandestine
26 Oct 2025
1929 Impressions
2 Retweets
18 Likes
6 Bookmarks
0 Replies
0 Quotes
(1/5) 🚨 CVE-2025-6514: Critical RCE in mcp-remote (CVSS 9.6) JFrog Security disclosed a command injection vulnerability in mcp-remote (v0.0.5-0.1.15) that achieves RCE when connecting to malicious MCP servers. A thread 🧵: -
@hackcubes
22 Oct 2025
24 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
https://t.co/T94EjyV1AY Vulnerability threatens LLM clients A security research team announces the discovery of a critical vulnerability in an MCP-remote server that allows remote code execution. The vulnerability, CVE-2025-6514 (CVSS score: 9,6), allows the execution of arbi
@B2bCyber
29 Sept 2025
36 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
MCP is powerful, but the security stakes are high. 🛡️ Prompt injection, tool poisoning, OAuth flaws (e.g. CVE-2025-6514), RCE risks. Case studies: SQLite MCP with SQL injection, Asana duped via multi-tenant exposure, Jira agents manipulated via prompts. Must-do’s: lea
@DataScienceDojo
17 Sept 2025
2161 Impressions
3 Retweets
10 Likes
2 Bookmarks
1 Reply
0 Quotes
Selling #nday #exploit for CVE-2025-6514 (mcp-remote) <= 0.1.15! Contact marshallwhittaker@gmail.com or dm for details! #Hacking #CyberSec #hackingtool #infosec https://t.co/NEfoLh6Sst
@oxagast
24 Aug 2025
12 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 A flaw in MCP-remote (CVE-2025-6514) has compromised 437K+ AI dev environments, turning into a massive #SoftwareSupplyChain attack. Learn how it happened and how to lock down your #AI workflows: https://t.co/IPLGUG2Ieh
@jfrog
14 Aug 2025
94 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
437,000+ downloads of a popular proxy. ⚠️ One malicious OAuth response. 💥 Your shell executes. Full RCE. This is CVE-2025-6514. 🧟♂️ MCP Horror Stories: Issue 2 breaks it down. Docker MCP shuts it down. 📖 Read it: https://t.co/Rmyfcn8LoG https://t.co/8VanUwB9
@Docker
7 Aug 2025
34194 Impressions
13 Retweets
49 Likes
12 Bookmarks
4 Replies
2 Quotes
Vulnerabilidad crítica en mcp-remote (CVE-2025-6514, CVSS 9.6) permite ejecución remota de código, afectando 437,000+ descargas. Actualiza a v0.1.16 y usa servidores MCP confiables con HTTPS. #Ciberseguridad #MCP https://t.co/1ho0KMWyfl
@taidynamics
6 Aug 2025
21 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
MCP adoption is surging—and July brought the first critical RCE in the toolchain: mcp-remote (CVE-2025-6514). If you connect to untrusted servers, you’re exposed. Update to 0.1.16. #MCP #AppSec #RCE https://t.co/B6Nc2ePKnn
@DeepEngineerHub
5 Aug 2025
30 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Critical RCE Vulnerability in mcp-remote: CVE-2025-6514 Threatens LLM Clients https://t.co/J3SHk7qywt
@_r_netsec
17 Jul 2025
1112 Impressions
2 Retweets
7 Likes
5 Bookmarks
1 Reply
0 Quotes
CVE-2025-6514: mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the authorization_endpoint response URL https://t.co/cufgwXpzlw
@ZeroDayFacts
16 Jul 2025
25 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
𝗖𝗥𝗜𝗧𝗜𝗖𝗔𝗟 𝗔𝗟𝗘𝗥𝗧: 𝗺𝗰𝗽-𝗿𝗲𝗺𝗼𝘁𝗲 𝗩𝘂𝗹𝗻 𝗘𝘅𝗽𝗼𝘀𝗲𝘀 𝗟𝗟𝗠 𝗖𝗹𝗶𝗲𝗻𝘁𝘀 𝘁𝗼 𝗥𝗲𝗺𝗼𝘁𝗲 𝗖𝗼𝗱𝗲 𝗘𝘅𝗲𝗰𝘂𝘁𝗶𝗼𝗻 (𝗖𝗩
@RootsOdin
15 Jul 2025
6 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Guess what? Like any tech, #MCP isn't immune to flaws. #CVE-2025-6514 affects NPM's mcp-remote MCP client library versions 0.5.0-0 through 0.1.15, allowing OS command injection via URL authentication when connecting to untrusted MCP servers – and yes, that means possible #RCE.
@CheckmarxZero
15 Jul 2025
73 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-6514 (CVSS:9.6, CRITICAL) is Awaiting Analysis. mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the aut..https://t.co/bHgpmcSVc7 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre
@cracbot
14 Jul 2025
8 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Critical RCE Vulnerability in mcp-remote: CVE-2025-6514 Threatens LLM Clients https://t.co/5bkdCatYZH #appsec
@eyalestrin
12 Jul 2025
22 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Warning: #CVE-2025-6514 (CVSS 9.6, CRITICAL) — #mcp-remote vulnerable to OS command injection via crafted input from malicious "authorization_endpoint" response. More info at: https://t.co/muUgDyjev2 #Patch #Patch #Patch
@CCBalert
11 Jul 2025
25 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Critical mcp-remote Vulnerability Enables Remote Code Execution, Impacting 437,000+ Downloads Critical vulnerabilities have been found in tools using Anthropic’s Model Context Protocol (MCP), posing major security risks. CVE-2025-6514 (CVSS 9.6) affects the "mcp-remote proxy",
@dCypherIO
11 Jul 2025
23 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
محققان آسیبپذیری بحرانی در پروژه متنباز mcp-remote کشف کردهاند که میتواند منجر به اجرای دستورات دلخواه سیستم عامل شود. این آسیبپذیری با شناسه CVE-2025-6514
@Teeegra
11 Jul 2025
565 Impressions
0 Retweets
13 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-6514: Command Injection in mcp-remote Turns Client Connections into Attack Vectors https://t.co/OdHRVnQoMU
@_cvereports
11 Jul 2025
17 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Vulnerabilità critica CVE-2025-6514: rischio RCE per client MCP-Remote nel mondo AI Vulnerabilità, AI, attacchi RCE, mcp, mcp-remote, rce https://t.co/aXn1MZ1gIU https://t.co/3pfLdONJRT
@matricedigitale
11 Jul 2025
32 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
10/07/2025 Critical mcp-remote vulnerability (CVE-2025-6514) enables RCE on 437,000+ systems! 🚨 With a CVSS score of 9.6, immediate patching is essential to mitigate risks. Source: https://t.co/TU1gLglnLv
@kernyx64
11 Jul 2025
8 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
A critical vulnerability in mcp-remote (CVE-2025-6514) affects versions up to 0.1.15, enabling remote code execution via malicious MCP servers. Over 437,000 downloads impacted; updates to 0.1.16 are recommended. ⚠️ #OpenSource #SecurityUK https://t.co/VELyMQ9o18
@TweetThreatNews
10 Jul 2025
38 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Critical flaw CVE-2025-6514 in mcp-remote project poses high-risk vulnerability. Addressing it is crucial for system security. https://t.co/wA7PT5jGIR #Cybersecurity #InfoSec
@threatlight
10 Jul 2025
36 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
RCE Vulnerability in mcp-remote: CVE-2025-6514 Threatens LLM Clients - https://t.co/kD0IG34ft5 https://t.co/eHCZQOo8HW
@AISecHub
10 Jul 2025
179 Impressions
0 Retweets
4 Likes
1 Bookmark
0 Replies
0 Quotes
🚨 Critical vulnerability (CVE-2025-6514) in mcp-remote enables FULL Remote Code Execution in LLM clients. The flaw affects Claude Desktop, Cursor & Windsurf apps connecting to untrusted MCP servers. First documented RCE case in MCP communications with CVSS score of 9.6.
@threatcluster
10 Jul 2025
6 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Critical RCE Vulnerability in mcp-remote: CVE-2025-6514 Threatens LLM Clients https://t.co/YZFdcreQbh
@Dinosn
10 Jul 2025
2235 Impressions
5 Retweets
11 Likes
3 Bookmarks
0 Replies
0 Quotes
Critical RCE Vulnerability in mcp-remote: CVE-2025-6514 Threatens LLM Clients https://t.co/J3SHk7qywt
@_r_netsec
9 Jul 2025
1940 Impressions
9 Retweets
15 Likes
7 Bookmarks
0 Replies
0 Quotes
[CVE-2025-6514: CRITICAL] mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the authorization_endpoint response URL#cve,CVE-2025-6514,#cybersecurity https://t.co/fKvXNHlcRI https://t.co/nxcPrhXHR8
@CveFindCom
9 Jul 2025
68 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes