logo

Critical mcp-remote Vulnerability Exposes LLM Clients to Remote Code Execution Attacks

ID: d23ca965-4997-5688-95f3-6eaa6922dfb0

STIX ID: report--d23ca965-4997-5688-95f3-6eaa6922dfb0

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2025-07-10

Date Updated: 2026-04-21

Author: Kaaviya

...
...

**Executive Summary:** The report details CVE-2025-6514, a critical RCE in mcp-remote (v0.0.5–0.1.15) where crafted OAuth authorization_endpoint values from untrusted or MITM-compromised MCP servers can trigger PowerShell command execution on Windows; remediation includes upgrading to v0.1.16, using HTTPS-only trusted MCP servers, and auditing client configurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.