mirror of
https://github.com/0xMarcio/cve.git
synced 2025-11-30 18:56:19 +00:00
1.2 KiB
1.2 KiB
CVE-2025-6514
Description
mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the authorization_endpoint response URL
POC
Reference
Github
- https://github.com/ARPSyndicate/cve-scores
- https://github.com/ChaseHCS/CVE-2025-6514
- https://github.com/asii-mov/mcproxy
- https://github.com/brightlikethelight/reliable-mcp
- https://github.com/chirag-gupta7/MCP-Website
- https://github.com/deepakchoudhary-dc/Your_MCP_Guardian
- https://github.com/galgantar/mcp-remote-cve
- https://github.com/nomi-sec/PoC-in-GitHub
- https://github.com/pringlized/mcp-sec
- https://github.com/pringlized/sMCP
- https://github.com/sm00thindian/mcp-cve-orchestrator