Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-c73c-x77g-854r | OpenClaude MCP OAuth Callback: State Check Bypass via error Param Leads to DoS |
Wed, 03 Jun 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gitlawb:openclaude:*:*:*:*:*:*:*:* |
Tue, 02 Jun 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gitlawb
Gitlawb openclaude |
|
| Vendors & Products |
Gitlawb
Gitlawb openclaude |
Tue, 02 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Jun 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the OpenClaude MCP authentication flow starts a temporary local HTTP server to handle OAuth callbacks. To prevent CSRF attacks, the server validates a state parameter against an internally stored value. However, due to a logic flaw in the order of conditionals, an attacker can completely bypass this check and force the server to shut down — without knowing the state value at all. This issue has been patched in version 0.5.1. | |
| Title | OpenClaude's MCP OAuth Callback: State Check Bypass via error Param Leads to DoS | |
| Weaknesses | CWE-352 CWE-400 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-02T17:40:55.678Z
Reserved: 2026-04-23T19:17:30.565Z
Link: CVE-2026-42073
Updated: 2026-06-02T17:37:38.903Z
Status : Analyzed
Published: 2026-06-02T17:16:31.910
Modified: 2026-06-03T16:54:29.273
Link: CVE-2026-42073
No data.
OpenCVE Enrichment
Updated: 2026-06-02T18:30:15Z
Github GHSA