Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-42073: OpenClaude MCP OAuth state check bypass allows callback server shutdown

In OpenClaude, an open-source coding-agent CLI, versions prior to 0.5.1 contained a logic flaw in the ordering of conditionals in the temporary local HTTP server used for MCP OAuth callbacks, letting an attacker bypass the anti-CSRF state parameter validation entirely and force the server to shut down without knowing the state value. The issue was patched in version 0.5.1.

Disclosed 2 June 2026 · Record updated 13 September 2026

Impact

An attacker could bypass CSRF state validation in the MCP authentication flow and shut down the local OAuth callback server without knowing the state value.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-42073