CVE-2025-6514 is a critical OS command injection vulnerability in the mcp-remote npm package. It affects versions 0.0.5 through 0.1.15 and occurs during the initial connection and authorization phase when mcp-remote processes authorization-related data received from a remote MCP server, specifically crafted input derived from the authorization_endpoint response URL. A malicious or attacker-controlled MCP server can supply crafted data that is incorporated into an operating system command executed by the client host. The issue can result in arbitrary command execution on Windows with full control over command parameters, and arbitrary executable invocation with more limited parameter control on macOS and Linux. Because mcp-remote is used as a local proxy between MCP clients and remote MCP servers, exploitation targets the client system that initiates the connection.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 4 candidates as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
30 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An OS command-injection vulnerability in MCP client/server interactions that can enable full remote code execution when clients connect to untrusted MCP servers.
A notable vulnerability mentioned in the context of MCP SSO implementation weaknesses, including manipulated discovery flows and client-side exploitation. Specific technical details are not provided in the content.
mcp-remote critical vulnerability enabling arbitrary OS command execution (RCE).
An arbitrary OS command execution vulnerability in mcp-remote that can be triggered when MCP clients connect to untrusted servers.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.