Web Hack List

Collected research

Critical RCE Vulnerability in mcp-remote: CVE-2025-6514 Threatens LLM Clients

Explains CVE-2025-6514 in mcp-remote, where an untrusted authorization endpoint can supply crafted metadata that reaches an operating-system command invocation. The write-up follows the OAuth discovery path to command injection and remote code execution in affected MCP clients.

Record

Researcher
@jfrog
Published by
JFrog
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of @jfrog, first published at the original source. Preserved copies are kept so the citation survives its host.