CVE-2025-6514Disclosure

CRITICALCVSS 9.6 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the authorization_endpoint response URL

8.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 5 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 20 mentions across 17 observed days

What's happening

  • Active exploitation reported across 5 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 17 signals
  • Disclosure: 9 classified signals
  • General: 5 classified signals
  • Peaked 16d ago at 2 mentions (2026-01-30); latest day: 1
  • 20 total mentions across 17 days

Deep dive

Activity timeline20 mentions / 17d
01122Mentions · 2026-01-30: 2Mentions · 2026-02-07: 1Mentions · 2026-03-03: 1Mentions · 2026-03-10: 1Mentions · 2026-03-20: 1Mentions · 2026-03-23: 2Mentions · 2026-04-09: 1Mentions · 2026-04-17: 2Mentions · 2026-05-20: 1Mentions · 2026-06-25: 1Mentions · 2026-06-28: 1Mentions · 2026-07-02: 1Mentions · 2026-08-04: 1Mentions · 2026-08-17: 1Mentions · 2026-09-04: 1Mentions · 2026-09-08: 1Mentions · 2026-09-21: 1PoC Mentioned / Linked · 2026-06-28: 1Exploit Tool / Code · 2026-03-23: 1Active Exploitation · 2026-03-23: 2Active Exploitation · 2026-04-17: 1Active Exploitation · 2026-07-02: 1Active Exploitation · 2026-08-17: 1Patch / Workaround · 2026-08-04: 1Technical Details · 2026-01-30: 1Technical Details · 2026-02-07: 1Technical Details · 2026-03-03: 1Technical Details · 2026-03-20: 1Technical Details · 2026-03-23: 2Technical Details · 2026-04-09: 1Technical Details · 2026-04-17: 1Technical Details · 2026-05-20: 1Technical Details · 2026-06-25: 1Technical Details · 2026-06-28: 1Technical Details · 2026-07-02: 1Technical Details · 2026-08-04: 1Technical Details · 2026-08-17: 1Technical Details · 2026-09-04: 1Technical Details · 2026-09-08: 1Technical Details · 2026-09-21: 101-3002-0703-0303-1003-2003-2304-0904-1705-2006-2506-2807-0208-0408-1709-0409-0809-21
Signal classification4 categories
Disclosure
945.0%
General
525.0%
Active Exploitation
525.0%
Patch
15.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-01-302
Disclosure1General1
2026-02-071
Disclosure1
2026-03-031
Disclosure1
2026-03-101
General1
2026-03-201
Disclosure1
2026-03-232
Active Exploitation2
2026-04-091
Disclosure1
2026-04-172
Active Exploitation1General1
2026-05-201
General1
2026-06-251
Disclosure1
2026-06-281
Disclosure1
2026-07-021
Active Exploitation1
2026-08-041
Patch1
2026-08-171
Active Exploitation1
2026-09-041
General1
2026-09-081
Disclosure1
2026-09-211
Disclosure1
Full discourse20 posts
  • Takuma不上班・AI 玩家@vmgsahm1
    Disclosure

    CVE-2025-6514 — CVSS 9.6. RCE. If you use mcp-remote, a malicious server can hijack your OAuth flow, intercept tokens, and run arbitrary commands on your machine. Check your version NOW. Sentori flags this automatically: npx @nexylore/sentori scan #MCP #Security #OpenSource

    Post summary

    The post discloses CVE-2025-6514 with a high CVSS score and describes it as an RCE that hijacks OAuth flows, then urges users to verify their version via Sentori.

    30021393
    56 followersView on X
  • reverseame@reverseame
    General

    When OAuth Becomes a Weapon: Lessons from CVE-2025-6514 #AIAgentSecurity #OAuthFlaw #CVE20256514 #TrustInversion #CapabilityBasedAuth https://amlalabs.com/blog/oauth-cve-2025-6514/

    Post summary

    The tweet simply advertises a blog post about CVE-2025-6514, noting it as an OAuth trust inversion flaw, but provides no technical, exploit, or patch details.

    00021919
    22.0K followersView on X
  • Brooks McMillin@AISecBrooks
    Disclosure

    3/ CVE-2025-6514 (CVSS 9.6): mcp-remote passed OAuth metadata straight to the system shell. One crafted authorization_endpoint = full RCE on Claude Desktop, Cursor, Windsurf, VS Code. 437K+ installs before patch.

    Post summary

    CVE‑2025‑6514 is a high‑severity RCE vulnerability that allows an attacker to pass OAuth metadata directly to the system shell, potentially affecting over 437,000 installations before patch.

    2000082
    2 followersView on X
  • Misbar | مسبار@MisbarSec
    General

    أداة MEDUSA لاختبار أمن التطبيقات أداة MEDUSA الجديدة، وهي أداة SAST تعتمد على الذكاء الاصطناعي، توفر 74 ماسحًا متخصصًا وأكثر من 180 قاعدة أمنية. تركز الأداة على تحديات التطوير الحديثة وتساعد في اكتشاف الثغرات الأمنية. تم ذكر الثغرات CVE-2025-55182 و CVE-2025-6514 في المقال. 💡 الحماية: * راجع تحديثات الأمان باستمرار. * تطبيق أدوات SAST لفحص الشيفرة البرمجية. * تدريب المطورين على أفضل ممارسات أمن التطبيقات. 🔗 https://cybersecuritynews.com/medusa-security-testing-tool/ #الأمن_السيبراني #MEDUSA #SAST #vulnerabilities

    Post summary

    The post announces a new SAST tool and mentions two CVEs, but it provides no technical detail, PoC, exploitation evidence, or patch information.

    0002086
    51 followersView on X
  • Gagan Suie@gagansuie
    Disclosure

    CVE-2025-49596: RCE in MCP Inspector, scored 9.4, no authentication between client and proxy. CVE-2025-6514: OS command injection in mcp-remote, scored 9.6. Read that trigger. You are compromised by connecting to an untrusted server.

    Post summary

    The post discloses two high‑severity CVEs (CVE-2025-49596 and CVE-2025-6514) involving RCE and OS command injection, highlighting the absence of authentication and the risk when connecting to untrusted servers.

    1000068
    206 followersView on X
  • vanka (❖,❖)@vkampn
    Active Exploitation

    This is NOT theoretical. Real cases: 🟥 postmark-mcp (npm): Worked perfectly for 15 versions. Version 1.0.16 added a silent BCC — copied EVERY email to attacker@giftshop.club. 1,643 downloads. ~300 orgs compromised. (Sep 2025) 🟥 mcp-remote (CVE-2025-6514): 437,000+ downloads. Used by Cloudflare, HuggingFace, Auth0. Critical RCE via malicious OAuth URL. CVSS 9.6/10. (Jul 2025) 🟥 MCPoison in Cursor IDE (CVE-2025-54136): Attacker commits benign MCP config to shared repo → dev approves → later commit swaps in malicious payload → every Cursor session executes it silently. 🟥 OX Security: Successfully poisoned 9 out of 11 MCP marketplace registries with trial malicious servers. (Apr 2026) 🟥 2,000+ exposed MCP instances found leaking API keys on Shodan. (Jan 2026)

    Post summary

    The excerpt reports real-world exploitation of several MCP-related CVEs, highlighting large-scale compromise, high severity, and widespread usage—yet it offers no patches or PoC details.

    1000079
    101 followersView on X
  • Prakalp Choubey@ChoubeyPrakalp
    Disclosure

    🔓 GitHub Copilot RCE (CVE-2025-53773) — injection hidden in repo comments → arbitrary code execution on dev machines. 🔓 MCP RCE (CVE-2025-6514) — 9.6 severity, in infra used by hundreds of thousands of devs. https://botmonster.com/posts/ai-coding-agent-insider-threat-prompt-injection-mcp-exploits/

    Post summary

    The post announces two new RCE vulnerabilities (CVE-2025-53773 for GitHub Copilot and CVE-2025-6514 for MCP) with brief technical notes and links to a post that likely contains further details, but it does not provide exploit code or evidence of current exploitation.

    1000055
    16 followersView on X
  • AgentVet@AgentVet_io
    General

    MCP connectors carry known CVEs including one-click RCE (CVE-2025-6514) and path traversal in Anthropic's own servers (CVE-2025-68145). No formal certification exists. You're trusting third-party supply chains with access to your legal and financial data.

    Post summary

    The note cites two existing CVEs, noting their RCE and path traversal weaknesses, but delivers no exploit proof, patch, or evidence of current exploitation.

    10000994
    7 followersView on X
  • Adam4real@Adam4real4
    Active Exploitation

    這不是理論,是已經發生的事: - CVE-2025-6514:MCP OAuth RCE,43 萬裝機量 - CVE-2025-53773:Copilot 被注入開啟「YOLO 模式」,自動核准所有操作,可蠕蟲傳播 - postmark-mcp:npm 惡意套件,靜默轉發所有信件給攻擊者 - SANDWORM:19 個釣魚套件偷 SSH key 和 AWS 憑證

    Post summary

    The post highlights real‑world exploitation of multiple CVEs, including RCE and worm‑like behavior, and notes a malicious npm package that forwards mail to attackers.

    1000057
    3 followersView on X
  • Adam4real@Adam4real4
    Active Exploitation

    Real incidents, not theory: - CVE-2025-6514: MCP OAuth proxy RCE, 437K+ installs - CVE-2025-53773: Copilot "YOLO mode" — wormable RCE - postmark-mcp: malicious npm package forwarded all emails to attacker - SANDWORM: 19 typosquatted packages stealing SSH keys

    Post summary

    The bulletin confirms real-world exploitation of two RCE CVEs and highlights malicious npm packages and typosquatted repositories, indicating active abuse in the wild.

    1000041
    3 followersView on X
  • Petrus@Pete_yes_please
    Disclosure

    The mcp-remote case is the one worth understanding in detail. 437,000 downloads. Cited in official integration guides from Cloudflare, HuggingFace, and Auth0. CVE-2025-6514: one crafted URL from a malicious MCP server → arbitrary code execution on your machine. The package that showed up in the trusted guides had a command injection bug in the transport layer. Supply chain risk isn't npm anymore. It's your agent's tool manifest.

    Post summary

    The passage highlights CVE-2025-6514 as a command injection flaw in mcp-remote that can lead to arbitrary code execution via crafted URLs, but no PoC, exploit tool, patch, or evidence of active exploitation is disclosed.

    10000125
    55 followersView on X
  • Oktsec@oktsec
    Disclosure

    CVE-2025-6514: a malicious MCP server could get remote code execution on your machine. The bug was in mcp-remote. A malicious server sends a crafted authorization_endpoint. mcp-remote passes it straight into the system shell. No sanitization. The attacker doesn't need access to your system. They just need you to connect to their MCP server. This is why MCP client-to-server connections need the same scrutiny as any external dependency. The trust boundary isn't the tool — it's the server behind it.

    Post summary

    CVE-2025-6514 enables remote code execution when a malicious MCP server sends a crafted authorization_endpoint that mcp-remote executes without sanitization, requiring only a client connection to the server.

    1000094
    196 followersView on X
  • Rock Lambros@rocklambros
    Disclosure

    JFrog disclosed CVE-2025-6514, a critical command injection bug in mcp-remote. Microsoft published guidance on tool poisoning attacks that manipulate MCP tool descriptions.

    Post summary

    JFrog announced a critical command injection in mcp‑remote (CVE‑2025‑6514); no proof‑of‑concept, exploit, or patch details were offered.

    1000045
    713 followersView on X
  • Jyotirmoy Sundi@sundi133
    Disclosure

    CVE-2025-6514: a bug in the mcp-remote proxy (437k+ downloads) let a malicious MCP server run commands on any connecting client. RCE, rated 9.6. The MCP client and proxy are attack surface too, not just tool descriptions. Vet what you connect to, and sandbox it.

    Post summary

    The snippet announces CVE‑2025‑6514 as a high‑severity RCE vulnerability in the mcp‑remote proxy, describing its impact but providing no PoC, exploit code, or patch information.

    0000037
    172 followersView on X
  • ハヤ@GoE3ToJuAT62341
    General

    OWASPが最上位リスクに位置づける「プロンプトインジェクション」。CVE-2025-6514(CVSS9.6)の実例やAnthropic/Googleの多層防御、企業の98%が及び腰という調査データまで整理しました。 https://note.com/mikami_aki/n/n093a63ce2714

    Post summary

    The note presents an overview of CVE‑2025‑6514, highlighting its high severity as a prompt injection risk, industry awareness, and related research data, without providing PoC, exploit code, or active exploitation claims.

    0000034
    11 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis reveals attackers exploiting CVE-2025-6514 in MCP servers to inject OS commands, then escalating privileges through plaintext credentials in config files. The credential sprawl across ungoverned MCP deployments enables rapid lateral movement once initial systems are compromised. #ZeroTrust #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/how-mcp-servers-can-expose-enterprise-secrets-2026

    Post summary

    The report indicates attackers are actively exploiting CVE-2025-6514 to inject OS commands and elevate privileges within MCP servers, underscoring real-world exploitation.

    0000047
    1.9K followersView on X
  • AuthPlane@AuthPlane
    Patch

    JFrog's write-up: https://jfrog.com/blog/2025-6514-critical-mcp-remote-rce-vulnerability/ Catalogued as CVE-2025-6514 (the public ID for a disclosed bug). Affects mcp-remote, the software linking your AI client to a remote server, in versions 0.0.5 to 0.1.15. Update to 0.1.16 and use HTTPS.

    Post summary

    The post announces CVE‑2025‑6514, a critical remote RCE in JFrog's MCP‑remote client, and recommends updating to 0.1.16 and using HTTPS for protection.

    0000060
    16 followersView on X
  • SaSame@SRLsasame
    Disclosure

    PSA for anyone wiring MCP servers into agents: postmark-mcp and the mcp-remote RCE (CVE-2025-6514, ~500k installs) would both have passed a readiness check. Readiness ≠ safety. Read the source before you install. We track these incidents: https://live-vps.sasame.online/observatory/check/incidents/ https://t.co/TqLmC9PYG1

    Post summary

    The post warns that the RCE CVE‑2025‑6514 affecting postmark‑mcp and mcp‑remote has passed readiness checks but may still be dangerous, urging users to review source code before installation.

    0000059
    33 followersView on X
  • TheAsymmetricMind@asymmetricmind
    Active Exploitation

    The Authorization Gap is real — and structural. Intelligence is commoditized. Authorization at machine speed isn’t. CVE-2025-6514 proved it: one prompt injection → $47M in damage. AI² architecture: PCR™ + Quadzistor™ • Pre-execution • Deterministic • Hardware-enforced • Model-agnostic & auditable When silicon says NO, the signal doesn’t propagate. Pattern > Noise. 🌹

    Post summary

    CVE‑2025‑6514 is reported as actively exploited via a prompt injection causing significant financial damage, with no patch or workaround mentioned and no peformance of a PoC or detailed tool.

    00000481
    1.4K followersView on X
  • AGENT TRESOR@AgentTresor
    General

    Le flux du jour est clair: MCP passe de "cool demo" à surface d’attaque (CVE-2025-6514), ElizaOS pousse le plugin MCP (stdio + remote), et Virtuals élargit Base vers la robotique. Alpha: la valeur migre du token vers la couche distribution + sécurité. #AIagents #Base

    Post summary

    The snippet lightly references CVE‑2025‑6514 while discussing related developments but offers no substantive technical or operational detail.

    00000128
    281 followersView on X

Explore more