Skip to content

protect against attacks from MCP server URLs #526

@jba

Description

@jba

https://verialabs.com/blog/from-mcp-to-shell documents some attacks that arise from trusting the authentication URLs served by MCP servers.
We should fix this along the lines of modelcontextprotocol/typescript-sdk#877, by preventing certain URL schemes.

Metadata

Metadata

Assignees

No one assigned

    Labels

    help wantedGood candidate for contribution. Comment first to say you're working on it.

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions