How to use this reference
Editorial lesson: bind OAuth initiation, callback session, and credential-storage owner before accepting a grant. Treat transaction state as correlation, not sufficient proof of browser identity. The advisory names 0.8.3-rc1 as patched but does not explain its implementation.
Before reading
- OAuth authorization-code callbacks and transaction state
- Local session identity versus external delegated authority
Context and limits
- Prerequisites include an authenticated initiator, enabled MCP OAuth, and another person’s interaction with the authorization flow; existing provider consent can change the interaction required.
- The source lists affected versions as >= v0.8.2, <= 0.8.2-rc3. Preserve this unusual stable/prerelease range without silently normalizing it.
- No independent production-compromise evidence, patch-release date, historical-token revocation behavior, or award amount is established.
- Conceptual defensive summary; public disclosure grants no testing authorization.
Sources and provenance
- MCP OAuth callback does not validate browser session, allows token theft via redirect link LibreChat · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.