Skip to content

mcp-remote exposed to OS command injection via untrusted MCP server connections

Critical severity GitHub Reviewed Published Jul 9, 2025 to the GitHub Advisory Database • Updated Jul 9, 2025

No open alerts for this advisory

Give feedback on Dependabot alerts