PT-2025-28894 · Unknown · Mcp-Remote
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
mcp-remote versions 0.0.5 through 0.1.15
Description
mcp-remote, a local proxy server that allows MCP clients to interact with remote servers, is susceptible to OS command injection. The issue occurs during the OAuth handshake when the proxy requests metadata from a remote server. A malicious server can provide a crafted
authorization endpoint response URL containing system commands. Due to improper sanitization, mcp-remote attempts to open this URL directly via the system shell, leading to arbitrary code execution on the client machine. On Windows, this allows full control over parameters, while on macOS and Linux, it enables the execution of arbitrary files with limited parameter control. The package had over 437,000 downloads.Recommendations
Update to version 0.1.16 or later.
Connect only to trusted MCP servers using secure connection methods such as HTTPS.
Exploit
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mcp-Remote