CVE-2025-6514mcp-remote OS command injection via authorization_endpoint
mcp-remote 0.0.5 to 0.1.15 could run OS commands planted by a malicious MCP server in its authorization_endpoint value. CVSS 9.6, fixed in 0.1.16.
What happened
mcp-remote is an npm package that connects MCP clients to remote MCP servers. JFrog found that versions 0.0.5 to 0.1.15 were open to OS command injection through the authorization_endpoint value a server supplies during authorisation. Connecting to a malicious MCP server was enough to run commands on the client machine.
The flaw is CVE-2025-6514, rated CVSS 9.6, and version 0.1.16 fixes it.
Why it worked
The client trusted metadata from the server it was connecting to and handled it in a way that reached the operating system's command line. Any server URL a user added became a route to code execution.
What to do
- Update mcp-remote to 0.1.16 or later and pin the version.
- Connect only to MCP servers you trust, and review new server URLs before adding them.
- Run MCP clients and bridges in a sandbox without access to your credentials.
Vet skills, plugins and MCP serversSandbox code and tool execution
Amazon Q Developer extension shipped with a wiper prompt
EscapeRoute: Filesystem MCP server sandbox escape
Work through the security checklist →