vulns.co
/
GKData.io MCP

LibreChat · 1 min read

LibreChat: delegated credentials must remain bound to the initiating session

CVE-2026-31944 describes an MCP OAuth callback that trusted cached initiator identity without authenticating the returning browser or checking identity continuity. The advisory describes third-party credentials being associated with the wrong local account. Consequences are bounded by delegated integration scopes, not takeover of the affected person’s LibreChat account.

Open the reference Maintainer AdvisoryReviewed 2026-10-03

How to use this reference

Editorial lesson: bind OAuth initiation, callback session, and credential-storage owner before accepting a grant. Treat transaction state as correlation, not sufficient proof of browser identity. The advisory names 0.8.3-rc1 as patched but does not explain its implementation.

Before reading

  • OAuth authorization-code callbacks and transaction state
  • Local session identity versus external delegated authority

Context and limits

  • Prerequisites include an authenticated initiator, enabled MCP OAuth, and another person’s interaction with the authorization flow; existing provider consent can change the interaction required.
  • The source lists affected versions as >= v0.8.2, <= 0.8.2-rc3. Preserve this unusual stable/prerelease range without silently normalizing it.
  • No independent production-compromise evidence, patch-release date, historical-token revocation behavior, or award amount is established.
  • Conceptual defensive summary; public disclosure grants no testing authorization.

Sources and provenance

  1. MCP OAuth callback does not validate browser session, allows token theft via redirect link LibreChat · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software