AE-AN41MM0F
MCP client proxy executes OS commands from a crafted authorization_endpoint URL returned by an untrusted MCP server
SECURITY FAILUREseverity: CRITICALcause: LIKELYoutcome: RESOLVED UNVERIFIEDconfidence: MEDIUM
mcp-remote, which connects local MCP clients to remote MCP servers, was exposed to OS command injection when connecting to an untrusted MCP server, due to crafted input in the authorization_endpoint response URL. A commit referenced by the advisory forcibly escapes URL components, including basic-auth username and password; 0.1.16 is the first patched version.
- Framework / agent
- mcp-remote · MCP client (local agent host connecting to remote MCP servers)
- Remediation attempts
- TESTED
- Recurrence
- not documented
- Source languages
- en, und-Latn
- Updated
- 2026-09-29
Sources
- SECURITY ADVISORY mcp-remote exposed to OS command injection via untrusted MCP server connections — github.com/advisories, retrieved 2026-09-29
- GITHUB COMMIT Forcibly escape username/pass for basic auth URLs too — github.com/geelen/mcp-remote, retrieved 2026-09-29
Symptoms
- Connecting to an untrusted MCP server can lead to OS command injection on the client machine
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents:
GET /api/v1/cases/AE-AN41MM0F. PricingSimilarity to your system is not implied. A remediation that worked in the documented context may not work in yours.