An OAuth error on the AI Playground reached a connected MCP server
The agent finding is the authority the session already held: a connected tool, not a confused sentence. Quote the low score the program disclosed. This card does not repeat the error value.
- Original severity
- Low (0.1 ~ 3.9) source-reported; not rescored by vulns.co
- Public source
- hackerone disclosure
- Program / vendor
- Cloudflare Public Bug Bounty
- Product / surface
- AI Playground OAuth handler and connected MCP servers
- Weakness
- Reflected cross-site scripting
- Affected boundary
- A signed-in Playground session and an MCP server that session had connected
- Disclosure date
- 2026-02-26
- Public status checked
- 2026-09-28
- Public attribution
- matured_kazama
What the evidence established
Cloudflare's summary says an OAuth error field was written into the page so that it ran in the site's origin, tracked as CVE-2026-1721. Their summary says that could read the signed-in chat or act on a connected MCP server for that session. They patched it and told Agents SDK users to upgrade to v0.3.10. The disclosed severity is a low range.
Why the impact was credible
The source reported session-scoped access to chat history and to MCP servers the victim had connected, after the victim opened a link.
Durable engineering lesson
The agent finding is the authority the session already held: a connected tool, not a confused sentence. Quote the low score the program disclosed. This card does not repeat the error value.
Control pattern
Encode the error field for the page context. Treat a connected MCP server as authority that a rendered error must not be able to call.
Primary public disclosure
Upstream availability and wording can change. Public status was last checked 2026-09-28.