TokyoTech-RCE Description The TokyoTech client has a flawed implementation where it fails to sanitize metadata during OAuth server discovery. Specifically, the URL provided by the server is passed directly to an insecure function. An attacker can exploit this by embedding a payload in the URL's authentication field, bypassing validation and achieving arbitrary OS command injection on the client's host machine. Vulnerable Code