CVE-2026-42073: OpenClaude MCP OAuth state check bypass allows callback server shutdown
In OpenClaude, an open-source coding-agent CLI, versions prior to 0.5.1 contained a logic flaw in the ordering of conditionals in the temporary local HTTP server used for MCP OAuth callbacks, letting an attacker bypass the anti-CSRF state parameter validation entirely and force the server to shut down without knowing the state value. The issue was patched in version 0.5.1.
Disclosed 2 June 2026 · Record updated 13 September 2026
Impact
An attacker could bypass CSRF state validation in the MCP authentication flow and shut down the local OAuth callback server without knowing the state value.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-42073
