Chronicle/Attacks & incidents

JFrog finds critical OS command injection in mcp-remote when connecting to untrusted MCP servers

AttackVulnerability disclosureSignificance assistant-drafted

JFrog reported CVE-2025-6514 (CVSS 9.6) in mcp-remote, a proxy used by MCP clients to reach remote servers, where a malicious server could supply a crafted OAuth authorization URL that led to command execution on the client machine. Versions 0.0.5 to 0.1.15 are affected and 0.1.16 fixes the issue.

Why it matters

Connecting an agent client to an untrusted MCP server could compromise the developer host, not just the conversation.

Key facts

As stated in the sources, with where to find them.

  • CVSS 9.6; affected versions 0.0.5 to 0.1.15; fixed in 0.1.16.Advisory header
  • Full arbitrary command execution on Windows; more limited executable launch on macOS and Linux.Impact section

Findings that cite this record

No tracked finding cites this record yet.

Key questions this bears on

Sources

Related records