{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/mcp-remote-cve-2025-6514-2025/",
 "asOf": "2026-09-26",
 "id": "mcp-remote-cve-2025-6514-2025",
 "date": "2025-07-09",
 "datePrecision": "day",
 "title": "JFrog finds critical OS command injection in mcp-remote when connecting to untrusted MCP servers",
 "lane": "attack",
 "kind": "vulnerability-disclosure",
 "summary": "JFrog reported CVE-2025-6514 (CVSS 9.6) in mcp-remote, a proxy used by MCP clients to reach remote servers, where a malicious server could supply a crafted OAuth authorization URL that led to command execution on the client machine. Versions 0.0.5 to 0.1.15 are affected and 0.1.16 fixes the issue.",
 "whyItMatters": "Connecting an agent client to an untrusted MCP server could compromise the developer host, not just the conversation.",
 "actors": [
  "jfrog"
 ],
 "topics": [
  "tool-and-mcp-security",
  "agent-supply-chain"
 ],
 "atlas": [
  "tools",
  "supply-chain"
 ],
 "artifacts": [],
 "sources": [
  {
   "url": "https://jfrog.com/blog/2025-6514-critical-mcp-remote-rce-vulnerability/",
   "publisher": "JFrog",
   "title": "Critical RCE Vulnerability in mcp-remote: CVE-2025-6514 Threatens LLM Clients",
   "date": "2025-07-09",
   "type": "primary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "CVSS 9.6; affected versions 0.0.5 to 0.1.15; fixed in 0.1.16.",
   "locator": "Advisory header"
  },
  {
   "fact": "Full arbitrary command execution on Windows; more limited executable launch on macOS and Linux.",
   "locator": "Impact section"
  }
 ],
 "significance": 3,
 "fideQuestions": [],
 "methods": [
  "malicious-agent-extensions",
  "tool-poisoning"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}