PT-2025-28894 · Unknown · Mcp-Remote

·

CVE-2025-6514

·

Published

2025-06-17

·

Updated

2026-07-02

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions mcp-remote versions 0.0.5 through 0.1.15
Description mcp-remote, a local proxy server that allows MCP clients to interact with remote servers, is susceptible to OS command injection. The issue occurs during the OAuth handshake when the proxy requests metadata from a remote server. A malicious server can provide a crafted authorization endpoint response URL containing system commands. Due to improper sanitization, mcp-remote attempts to open this URL directly via the system shell, leading to arbitrary code execution on the client machine. On Windows, this allows full control over parameters, while on macOS and Linux, it enables the execution of arbitrary files with limited parameter control. The package had over 437,000 downloads.
Recommendations Update to version 0.1.16 or later. Connect only to trusted MCP servers using secure connection methods such as HTTPS.

Exploit

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-09316
CVE-2025-6514
GHSA-6XPM-GGF7-WC3P

Affected Products

Mcp-Remote