Collected research
Critical RCE Vulnerability in mcp-remote: CVE-2025-6514 Threatens LLM Clients
Explains CVE-2025-6514 in mcp-remote, where an untrusted authorization endpoint can supply crafted metadata that reaches an operating-system command invocation. The write-up follows the OAuth discovery path to command injection and remote code execution in affected MCP clients.
Record
- Researcher
- @jfrog
- Published by
- JFrog
- Date
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of @jfrog, first published at the original source. Preserved copies are kept so the citation survives its host.