Cato CTRL™ Threat Research: Two Vulnerabilities in Anthropic’s MCP SDK Enable OAuth Token Theft and Supply Chain Attacks
ID: 74f0266c-0cb0-5a4b-83e4-033b82102e5e
STIX ID: report--74f0266c-0cb0-5a4b-83e4-033b82102e5e
Feed Name: Cato Networks
Threat Score
Cato CTRL researchers disclosed two default-permissive vulnerabilities in Anthropic’s MCP SDK—wildcard CORS and unvalidated redirect URIs—that enable browser-based OAuth token theft; a provided proof-of-concept shows how stolen developer tokens could be used to hijack CI/CD workflows and produce signed malicious updates, presenting a high-risk software supply-chain attack vector and recommending immediate configuration and network mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
