mcp-remote
Remote proxy for Model Context Protocol, allowing local-only clients to connect to remote servers using oAuth
Installing this server brings 81 third-party packages inside your agent's trust boundary (4 direct). This is attack surface, not a vulnerability count — it does not affect the grade above.
Findings (1)
- HIGH
VULN_KNOWN— GHSA-6xpm-ggf7-wc3p: mcp-remote exposed to OS command injection via untrusted MCP server connections. See https://osv.dev/vulnerability/GHSA-6xpm-ggf7-wc3p
Embed this badge
[](https://vulnrable.com/mcp/mcp-remote/) Automated registry-metadata scan; not a code audit. Rescanned on each site deploy.