Critical RCE Vulnerability in mcp-remote: CVE-2025-6514 Threatens LLM Clients
jfrog.com | research | CVE-2025-6514 | #ai-security | #rce | #mcp | #jfrog | #cve-2025-6514 | #mcp-remote
Summary
JFrog discloses CVE-2025-6514 (CVSS 9.6) in mcp-remote 0.0.5-0.1.15: connecting to untrusted MCP servers lets attackers run OS commands — the first real-world RCE via MCP clients; fixed in 0.1.16.
- Published
- Collected
Skip to content