geelen/mcp-remote

geelen/mcp-remote

Releases61
Frequency5 days 7 hours
Last Release
Stars1.47K

CVE History

CVEPublishedCVSS v3CVSS v2
9.6 CRITICAL

mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the authorization_endpoint response URL