mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the authorization_endpoint response URL
2025-07-09T13:15:24.213
2025-07-10T13:17:30.017
Awaiting Analysis
[email protected]
CVSSv3.1: 9.6 (CRITICAL)
-