mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the authorization_endpoint response URL
| Software | From | Fixed in |
|---|---|---|
mcp-remote
|
0.0.5 | 0.1.16 |