vulns.co
/
GKData.io MCP

Back to Reports

An OAuth error on the AI Playground reached a connected MCP server

The agent finding is the authority the session already held: a connected tool, not a confused sentence. Quote the low score the program disclosed. This card does not repeat the error value.

Editorial decision card. This page links to a source-verified public disclosure and contains only original defensive analysis. It does not mirror upstream HTML, payloads, attachments, private submissions, or exploit steps.
Original severity
Low (0.1 ~ 3.9) source-reported; not rescored by vulns.co
Public source
hackerone disclosure
Program / vendor
Cloudflare Public Bug Bounty
Product / surface
AI Playground OAuth handler and connected MCP servers
Weakness
Reflected cross-site scripting
Affected boundary
A signed-in Playground session and an MCP server that session had connected
Disclosure date
2026-02-26
Public status checked
2026-09-28
Public attribution
matured_kazama

What the evidence established

Cloudflare's summary says an OAuth error field was written into the page so that it ran in the site's origin, tracked as CVE-2026-1721. Their summary says that could read the signed-in chat or act on a connected MCP server for that session. They patched it and told Agents SDK users to upgrade to v0.3.10. The disclosed severity is a low range.

Why the impact was credible

The source reported session-scoped access to chat history and to MCP servers the victim had connected, after the victim opened a link.

Durable engineering lesson

The agent finding is the authority the session already held: a connected tool, not a confused sentence. Quote the low score the program disclosed. This card does not repeat the error value.

Control pattern

Encode the error field for the page context. Treat a connected MCP server as authority that a rendered error must not be able to call.

Primary public disclosure

Read the original source ↗

Upstream availability and wording can change. Public status was last checked 2026-09-28.