What happened
A malicious MCP server returned a crafted authorization_endpoint URL containing shell metacharacters in its OAuth metadata. When mcp-remote processed this URL during the OAuth flow, the metacharacters executed arbitrary shell commands on the developer's machine.