Description

mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the authorization_endpoint response URL

INFO

Published Date :

2025-07-09T12:41:44.921Z

Last Modified :

2025-07-09T13:06:05.402Z

Source :

JFROG
AFFECTED PRODUCTS

The following products are affected by CVE-2025-6514 vulnerability.

No data.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact