Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      CodeSOD: A Unique Way to Primary Key

      July 22, 2025

      BrowserStack launches Figma plugin for detecting accessibility issues in design phase

      July 22, 2025

      Parasoft brings agentic AI to service virtualization in latest release

      July 22, 2025

      Node.js vs. Python for Backend: 7 Reasons C-Level Leaders Choose Node.js Talent

      July 21, 2025

      The best CRM software with email marketing in 2025: Expert tested and reviewed

      July 22, 2025

      This multi-port car charger can power 4 gadgets at once – and it’s surprisingly cheap

      July 22, 2025

      I’m a wearables editor and here are the 7 Pixel Watch 4 rumors I’m most curious about

      July 22, 2025

      8 ways I quickly leveled up my Linux skills – and you can too

      July 22, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      The Intersection of Agile and Accessibility – A Series on Designing for Everyone

      July 22, 2025
      Recent

      The Intersection of Agile and Accessibility – A Series on Designing for Everyone

      July 22, 2025

      Zero Trust & Cybersecurity Mesh: Your Org’s Survival Guide

      July 22, 2025

      Execute Ping Commands and Get Back Structured Data in PHP

      July 22, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      A Tomb Raider composer has been jailed — His legacy overshadowed by $75k+ in loan fraud

      July 22, 2025
      Recent

      A Tomb Raider composer has been jailed — His legacy overshadowed by $75k+ in loan fraud

      July 22, 2025

      “I don’t think I changed his mind” — NVIDIA CEO comments on H20 AI GPU sales resuming in China following a meeting with President Trump

      July 22, 2025

      Galaxy Z Fold 7 review: Six years later — Samsung finally cracks the foldable code

      July 22, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Tech & Work»JFrog finds MCP-related vulnerability, highlighting need for stronger focus on security in MCP ecosystem

    JFrog finds MCP-related vulnerability, highlighting need for stronger focus on security in MCP ecosystem

    July 11, 2025

    Earlier this week, JFrog disclosed CVE-2025-6514, a critical vulnerability in the mcp-remote project that could allow an attacker to “trigger arbitrary OS command execution on the machine running mcp-remote when it initiates a connection to an untrusted MCP server.” 

    Mcp-remote is a project that allows LLM hosts to communicate with remote MCP servers, even if they only natively support communicating with local MCP servers, JFrog explained. 

    “While previously published research has demonstrated risks from MCP clients connecting to malicious MCP servers, this is the first time that full remote code execution is achieved in a real-world scenario on the client operating system when connecting to an untrusted remote MCP server,” Or Peles, vulnerability research team leader at JFrog, wrote in a blog post.

    Glen Maddern, mcp-remote’s primary maintainer, quickly fixed the vulnerability, so anyone using mcp-remote should update to 0.1.16.  

    According to Peles, the moral of the story here is that MCP users should only connect to trusted MCP servers and should be using secure connection methods like HTTPS, since similar vulnerabilities could be found in the future. “Otherwise, vulnerabilities like CVE-2025-6514 are likely to hijack MCP clients in the ever-growing MCP ecosystem,” Peles said. 

    Addressing security concerns in the broader MCP ecosystem

    JFrog’s discovery isn’t the first vulnerability related to MCP to come to light. Other recent CVEs include CVE-2025-49596, which detailed MCP Inspector being vulnerable to remote code execution (fixed in version 0.14.1); CVE-2025-53355, which detailed a command injection vulnerability in MCP Server Kubernetes (fixed in version 2.5.0); and CVE-2025-53366, which detailed a validation error in the MCP Python SDK that could lead to an unhandled exception when processing malformed requests (fixed in version 1.9.4). 

    According to the MCP documentation, some of the most common attacks in MCP are confused deputy problems, token passthrough, and session hijacking.

    Gaetan Ferry, a security researcher at secrets management company GitGuardian, said “My current feeling about the protocol itself right now is that it’s not gatmature enough from a security perspective. So if even the protocol itself is not mature security-wise, you can’t really expect the ecosystem to be mature security-wise.”

    He predicts we’re going to continue seeing more CVEs pop up as MCP adoption increases, and noted that right now we’re seeing a new exploitation scenario roughly every two weeks.  

    He said that there isn’t yet an industry consensus on best practices for using MCP safely, but some recommendations are starting to come out. His biggest recommendation is to install servers in unique trust boundaries. For example, one installation would be only for dealing with sensitive data, and another could be designated for only working with untrusted data. 

    Despite the lack of security in MCP, Ferry believes it’s still possible to use MCP safely if you are conscious about what you are doing when you use it. GitGuardian uses MCP internally, but it has specific guidelines that must be followed and restricts the kinds of features, servers, and data they can use. 

    The problem, he said, is that MCP is so young and adoption has been quick, and often when you try to go fast, security is not the first thing that is thought about. We’re past the point of no return now, with so many already having adopted it, so now we need to move forward with security top of mind. 

    “It’s going to be a challenge for the industry, but that’s something we’ve already faced in the past every time the industry comes up with a new exciting technology,” he said. “Microservices and APIs at some point were also kind of a revolution, and we saw the same patterns like old attacks starting to work again in a new environment, and a whole new security environment needing to be built.”

    The post JFrog finds MCP-related vulnerability, highlighting need for stronger focus on security in MCP ecosystem appeared first on SD Times.

    Source: Read More 

    news
    Facebook Twitter Reddit Email Copy Link
    Previous ArticlePaddy Power and BetFair have suffered a data breach
    Next Article This week in AI dev tools: Gemini API Batch Mode, Amazon SageMaker AI updates, and more (July 11, 2025)

    Related Posts

    Tech & Work

    CodeSOD: A Unique Way to Primary Key

    July 22, 2025
    Tech & Work

    BrowserStack launches Figma plugin for detecting accessibility issues in design phase

    July 22, 2025
    Leave A Reply Cancel Reply

    For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

    Continue Reading

    Not Just Delight: Negative Emotions in UX Design

    Web Development

    Rethinking layout in Sketch with Stacks

    Web Development

    CVE-2025-2254 – GitLab Cross-Site Scripting (XSS) Vulnerability

    Common Vulnerabilities and Exposures (CVEs)

    Course: WordPress Theme Development (Core Concepts)

    Development

    Highlights

    Development

    Larallow is a Permissions Package With Support for Scopes

    June 17, 2025

    Larallow for Laravel is a package for handling roles and permissions with advanced features such…

    I replaced my Pixel 9 Pro with this $700 Android phone, and didn’t mind that it’s for gamers

    June 3, 2025

    Aflac, one of the USA’s largest insurers, is the latest to fall “under siege” to hackers

    June 24, 2025

    CVE-2025-5826 – Autel MaxiCharger AC Wallbox Commercial BLE Command Injection Vulnerability

    June 25, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.