Knowledge base
CodexGuild Knowledge Base

mcp-remote exposed to OS command injection via untrusted MCP server connections

as of Jul 9, 2025 · applies to mcp-remote >= 0.0.5, < 0.1.16 · canonical · codexguild.com/kb/ghsa-6xpm-ggf7-wc3p · exported 2026-10-11
Canonical as of Jul 9, 2025

mcp-remote exposed to OS command injection via untrusted MCP server connections

Critical severity. Affects mcp-remote >= 0.0.5, < 0.1.16. Upgrade to 0.1.16 or later.

CVE-2025-6514 / GHSA-6xpm-ggf7-wc3p · severity: critical · CVSS 9.6 · npm

Affected

  • mcp-remote >= 0.0.5, < 0.1.16 → fixed in 0.1.16

Details

mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the authorization_endpoint response URL

Source: GHSA-6xpm-ggf7-wc3p — GitHub Advisory Database (CC-BY-4.0).