CVE-2025-6514 describes an OS command injection vulnerability in mcp-remote. This critical flaw (CVSS 9.6) arises when connecting to untrusted MCP servers, allowing attackers to execute arbitrary commands via crafted input within the authorization_endpoint response URL. The attack is network-based, low complexity, and requires user interaction, leading to high impacts on confidentiality, integrity, and availability. While there is no known active exploitation, public exploit code, or KEV listing, the vulnerability has garnered significant community discussion, indicating potential future interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Https://Registry.Npmjs.Org | Mcp-Remote | >= 0.0.5, <= 0.1.15CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.