JFrog’s security research team disclosed CVE-2025-6514 on July 9, 2025, a critical OS command injection vulnerability (CVSS 9.6) in the mcp-remote npm package used to bridge AI clients such as Claude Desktop to remote Model Context Protocol servers over HTTP. The flaw, present in versions 0.0.5 through 0.1.15, could let a malicious or compromised MCP server achieve full remote code execution on the connecting client’s operating system. The package had been downloaded more than 437,000 times before a fix shipped in version 0.1.16, with no confirmed real-world exploitation reported.