---
title: "mcp-remote OS command injection via authorization_endpoint · DotsAgent"
description: "mcp-remote 0.0.5 to 0.1.15 could run OS commands planted by a malicious MCP server in its authorization_endpoint value. CVSS 9.6, fixed in 0.1.16."
url: https://dotsagent.io/security/incidents/2025-07-mcp-remote-os-command-injection
---

July 9, 2025

CVE-2025-6514

# mcp-remote OS command injection via authorization_endpoint

mcp-remote 0.0.5 to 0.1.15 could run OS commands planted by a malicious MCP server in its authorization_endpoint value. CVSS 9.6, fixed in 0.1.16.

## What happened

mcp-remote is an npm package that connects MCP clients to remote MCP servers. JFrog found that versions 0.0.5 to 0.1.15 were open to OS command injection through the authorization_endpoint value a server supplies during authorisation. Connecting to a malicious MCP server was enough to run commands on the client machine.

The flaw is CVE-2025-6514, rated CVSS 9.6, and version 0.1.16 fixes it.

## Why it worked

The client trusted metadata from the server it was connecting to and handled it in a way that reached the operating system's command line. Any server URL a user added became a route to code execution.

## What to do

- Update mcp-remote to 0.1.16 or later and pin the version.
- Connect only to MCP servers you trust, and review new server URLs before adding them.
- Run MCP clients and bridges in a sandbox without access to your credentials.

[Vet skills, plugins and MCP servers](https://dotsagent.io/security#supplyChainVetting)[Sandbox code and tool execution](https://dotsagent.io/security#sandboxing)

- [Amazon Q Developer extension shipped with a wiper prompt](https://dotsagent.io/security/incidents/2025-07-amazon-q-wiper-prompt)

- [EscapeRoute: Filesystem MCP server sandbox escape](https://dotsagent.io/security/incidents/2025-07-filesystem-mcp-escaperoute)

[Work through the security checklist →](https://dotsagent.io/security/checklist)

## Sources

1. [jfrog.com](https://jfrog.com/blog/2025-6514-critical-mcp-remote-rce-vulnerability/)/blog/2025-6514-critical-mcp-remote-rce-vulnerability/

Independent reference for people who build AI agents. Not affiliated with any vendor named here.

© 2026 DotsAgent · Facts checked October 1, 2026
