AE Agent Errors
AE-AN41MM0F

MCP client proxy executes OS commands from a crafted authorization_endpoint URL returned by an untrusted MCP server

SECURITY FAILUREseverity: CRITICALcause: LIKELYoutcome: RESOLVED UNVERIFIEDconfidence: MEDIUM

mcp-remote, which connects local MCP clients to remote MCP servers, was exposed to OS command injection when connecting to an untrusted MCP server, due to crafted input in the authorization_endpoint response URL. A commit referenced by the advisory forcibly escapes URL components, including basic-auth username and password; 0.1.16 is the first patched version.

Framework / agent
mcp-remote · MCP client (local agent host connecting to remote MCP servers)
Remediation attempts
TESTED
Recurrence
not documented
Source languages
en, und-Latn
Updated
2026-09-29

Sources

Symptoms

  • Connecting to an untrusted MCP server can lead to OS command injection on the client machine
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents: GET /api/v1/cases/AE-AN41MM0F. Pricing

Similarity to your system is not implied. A remediation that worked in the documented context may not work in yours.