{"id":79208,"date":"2026-06-02T20:46:31","date_gmt":"2026-06-02T17:16:31","guid":{"rendered":"https:\/\/afaghhosting.net\/blog\/cve-2026-42073-openclaudes-mcp-oauth-callback-state-check-bypass-via-error-param-leads-to-dos\/"},"modified":"2026-06-02T20:46:31","modified_gmt":"2026-06-02T17:16:31","slug":"cve-2026-42073-openclaudes-mcp-oauth-callback-state-check-bypass-via-error-param-leads-to-dos","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/cve-2026-42073-openclaudes-mcp-oauth-callback-state-check-bypass-via-error-param-leads-to-dos\/","title":{"rendered":"CVE-2026-42073 &#8211; OpenClaude&#8217;s MCP OAuth Callback: State Check Bypass via error Param Leads to DoS"},"content":{"rendered":"<p>CVE ID :CVE-2026-42073<\/p>\n<p>  Published : June 2, 2026, 5:16 p.m. | 1\u00a0hour, 16\u00a0minutes ago<\/p>\n<p>  Description :OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the OpenClaude MCP authentication flow starts a temporary local HTTP server to handle OAuth callbacks. To prevent CSRF attacks, the server validates a state parameter against an internally stored value. However, due to a logic flaw in the order of conditionals, an attacker can completely bypass this check and force the server to shut down \u2014 without knowing the state value at all. This issue has been patched in version 0.5.1.<\/p>\n<p>  Severity: 6.5 | MEDIUM<\/p>\n<p>  Visit the link for more details, such as CVSS details, affected products, timeline, and more&#8230;\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CVE ID :CVE-2026-42073 Published : June 2, 2026, 5:16 p.m. | 1\u00a0hour, 16\u00a0minutes ago Description :OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the OpenClaude MCP authentication flow starts a temporary local HTTP server to handle OAuth callbacks. To prevent CSRF attacks, the server validates &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-79208","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/79208","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=79208"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/79208\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=79208"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=79208"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=79208"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}