mcp-remote.authorization_endpoint.Command.Injection

2026-03-11 This signature was removed in version 35.182.

description-logoDescription

This indicates an attack attempt to exploit a Command Injection vulnerability in mcp-remote.
The vulnerability is due to an error in the application when handling a maliciously crafted response. A remote attacker may exploit this to execute arbitrary code within the context of the application.

affected-products-logoAffected Products

mcp-remote versions 0.0.5 through 0.1.15

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Apply the most recent upgrade or patch from the vendor.
https://github.com/geelen/mcp-remote

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Status Detail
2026-03-11 35.182
Removed
2025-07-24 33.052
Modified
Default_action:pass:drop
2025-07-16 33.046
New