dotsagent.io
Language:English
CVE-2025-6514

mcp-remote OS command injection via authorization_endpoint

mcp-remote 0.0.5 to 0.1.15 could run OS commands planted by a malicious MCP server in its authorization_endpoint value. CVSS 9.6, fixed in 0.1.16.

What happened

mcp-remote is an npm package that connects MCP clients to remote MCP servers. JFrog found that versions 0.0.5 to 0.1.15 were open to OS command injection through the authorization_endpoint value a server supplies during authorisation. Connecting to a malicious MCP server was enough to run commands on the client machine.

The flaw is CVE-2025-6514, rated CVSS 9.6, and version 0.1.16 fixes it.

Why it worked

The client trusted metadata from the server it was connecting to and handled it in a way that reached the operating system's command line. Any server URL a user added became a route to code execution.

What to do

  • Update mcp-remote to 0.1.16 or later and pin the version.
  • Connect only to MCP servers you trust, and review new server URLs before adding them.
  • Run MCP clients and bridges in a sandbox without access to your credentials.

Vet skills, plugins and MCP serversSandbox code and tool execution

Work through the security checklist →

Sources

  1. jfrog.com/blog/2025-6514-critical-mcp-remote-rce-vulnerability/

Independent reference for people who build AI agents. Not affiliated with any vendor named here.

© 2026 DotsAgent · Facts checked October 1, 2026