Veria Labs has announced that there is an issue with the authentication process when connecting to MCP servers using coding tools such as Claude Code and Gemini CLI. The cause is that clients over-trust the authentication URLs sent by malicious MCP servers. According to the report, this allows attackers to gain complete control over the user's PC.
MCP Auth Flaws Enable RCE in Claude Code and Others, Veria Labs Reports
This article is a translation. Read the Japanese original
The specific vulnerability lies in the handling of redirect URLs within the OAuth flow. When window.open() is executed for a URL specified by the server, an XSS occurs if a javascript: scheme URL is passed. In the case of the use-mcp library created by Cloudflare, this flaw reportedly allows arbitrary JavaScript to be executed in the user's browser.
The scope of impact is broad, with reports stating it extends to Anthropic's MCP Inspector and ChatGPT. The company pointed out that they discovered this pattern in June and that it existed in libraries with over 30,000 weekly downloads on npm.
Sources: From MCP to shell: MCP auth flaws enable RCE in Claude Code, Gemini CLI and more(HN 148pt・40コメント)(HN Search (backfill), 2025-09-24)