SSRF Vulnerability Found in AI SDK's OAuth Metadata Discovery Flow
A security researcher discovered a server-side request forgery (SSRF) vulnerability in a popular AI SDK used to handle authentication for MCP servers, which allow AI applications to connect to external tools and data sources. The flaw existed in the SDK's OAuth metadata discovery process, where a developer-supplied server URL is fetched without any validation. While the codebase included a URL-validation function applied to credential submission endpoints, it was never called during the metadata discovery chain. A proof-of-concept test confirmed the SDK would connect to internal addresses, including 127.0.0.1, without restriction. The gap highlights how partial security controls can leave critical code paths exposed, especially in fast-moving AI tooling development.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in