CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.6. Public exploit code or proof-of-concept references have been detected in its references. Its EPSS score suggests a 77.5% probability of exploitation in the next 30 days. It may be remotely exploitable.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
GitHub PoC Links
Note: these links are listed for security research and verification purposes only.
CVE
CVE-2025-6514
Severity
CRITICAL
CVSS
9.6
EPSS
77.55%
Original NVD Description
mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the authorization_endpoint response URL