CVE-2025-6514: exploitation status and patch state
CVE-2025-6514 · CVSS 9.6 CRITICAL · EPSS 78%
mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the authorization_endpoint response URL
Is CVE-2025-6514 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at 78%.
Public exploit code: none found in monitored sources.