{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-17T18:55:08.801","vulnerabilities":[{"cve":{"id":"CVE-2025-6514","sourceIdentifier":"reefs@jfrog.com","published":"2025-07-09T13:15:24.213","lastModified":"2026-06-17T10:02:03.283","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the authorization_endpoint response URL"},{"lang":"es","value":"mcp-remote está expuesto a la inyección de comandos del sistema operativo cuando se conecta a servidores MCP no confiables debido a una entrada manipulada desde la URL de respuesta de autorización_endpoint"}],"affected":[{"source":"reefs@jfrog.com","affectedData":[{"defaultStatus":"unaffected","collectionURL":"https://registry.npmjs.org","packageName":"mcp-remote","versions":[{"version":"0.0.5","lessThanOrEqual":"0.1.15","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"reefs@jfrog.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","baseScore":9.6,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":6.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-07-09T13:05:52.266929Z","id":"CVE-2025-6514","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"reefs@jfrog.com","type":"Secondary","description":[{"lang":"en","value":"CWE-78"}]}],"references":[{"url":"https://github.com/geelen/mcp-remote/commit/607b226a356cb61a239ffaba2fb3db1c9dea4bac","source":"reefs@jfrog.com"},{"url":"https://jfrog.com/blog/2025-6514-critical-mcp-remote-rce-vulnerability","source":"reefs@jfrog.com"},{"url":"https://research.jfrog.com/vulnerabilities/mcp-remote-command-injection-rce-jfsa-2025-001290844/","source":"reefs@jfrog.com"}]}}]}