2 Sources
[1]
Critical mcp-remote Vulnerability Enables Remote Code Execution, Impacting 437,000+ Downloads
Cybersecurity researchers have discovered a critical vulnerability in the open-source mcp-remote project that could result in the execution of arbitrary operating system (OS) commands. The vulnerability, tracked as CVE-2025-6514, carries a CVSS score of 9.6 out of 10.0. "The vulnerability allows
[2]
JFrog : Security Research Team Discovers Critical Remote Code Execution Vulnerability Hijacking mcp-remote Clients
Sunnyvale, Calif. - July 9, 2025- Today, the JFrog Security Research team announced its discoveryof a critical vulnerability in an mcp-remoteserver capable of performing remote code execution. The vulnerability, CVE-2025-6514(CVSS 9.6score), is capable of triggering arbitrary OS command execution
Share
Copy Link
A critical vulnerability in the mcp-remote tool, used for connecting AI applications to remote servers, has been discovered. This flaw could allow attackers to execute arbitrary code on users' systems, potentially leading to full system compromise.
Cybersecurity researchers from JFrog have uncovered a critical vulnerability in the open-source mcp-remote project, a tool widely used in the AI community. The flaw, tracked as CVE-2025-6514 with a CVSS score of 9.6 out of 10.0, could allow attackers to execute arbitrary operating system commands on machines running mcp-remote when connecting to untrusted Model Context Protocol (MCP) servers
1
.
Source: Hacker News
The vulnerability affects mcp-remote versions 0.0.5 to 0.1.15, impacting over 437,000 downloads. Or Peles, JFrog Vulnerability Research Team Leader, emphasized the severity of the issue, stating that it poses "a significant risk to users - a full system compromise"
2
.The vulnerability stems from how mcp-remote processes commands during the initial communication and authorization phase with an MCP server. A malicious server could embed a command that, when processed by mcp-remote, executes on the client's operating system. The impact varies across platforms:
1
Mcp-remote emerged following Anthropic's release of the Model Context Protocol (MCP), an open-source framework for standardizing how large language model (LLM) applications integrate with external data sources and services. It acts as a local proxy, enabling MCP clients like Claude Desktop to communicate with remote MCP servers
1
.This vulnerability is particularly significant as it represents the first instance of achieving full remote code execution in a real-world scenario on the client operating system when connecting to an untrusted remote MCP server
1
.Related Stories
JFrog has addressed the vulnerability in mcp-remote version 0.1.16, released on June 17, 2025. To mitigate the risk, users are strongly advised to:
2
This discovery highlights the growing importance of security in the AI ecosystem. As AI applications increasingly rely on external data sources and services, vulnerabilities in the tools facilitating these connections can have far-reaching consequences.
The incident follows recent disclosures of other vulnerabilities in the MCP ecosystem, including:
1
These vulnerabilities underscore the need for robust security practices in the development and deployment of AI-related tools and infrastructure.
Summarized by
Navi
[1]
17 Apr 2026•Technology

20 Jan 2026•Technology

02 Aug 2025•Technology

1
Science and Research

2
Policy and Regulation

3
Technology