JFrog reported CVE-2025-6514 (CVSS 9.6) in mcp-remote, a proxy used by MCP clients to reach remote servers, where a malicious server could supply a crafted OAuth authorization URL that led to command execution on the client machine. Versions 0.0.5 to 0.1.15 are affected and 0.1.16 fixes the issue.
Why it matters
Connecting an agent client to an untrusted MCP server could compromise the developer host, not just the conversation.
Key facts
As stated in the sources, with where to find them.
- CVSS 9.6; affected versions 0.0.5 to 0.1.15; fixed in 0.1.16.Advisory header
- Full arbitrary command execution on Windows; more limited executable launch on macOS and Linux.Impact section
Findings that cite this record
No tracked finding cites this record yet.
Key questions this bears on
- Where are deployed AI agents actually being exploited?Mostly around the model: connectors, credentials, tools, and packages, rather than the model alone.
Sources
Related records
Aug 5, 2025
Sep 25, 2025
Apr 1, 2025
Mar 30, 2025
Apr 15, 2026
Aug 26, 2025