build1 publisher
QRFLOW.codes traced its MCP OAuth exposure to a consent screen that trusted registrant-chosen names
QRFLOW.codes' developer refused both fixes a security report proposed for open OAuth client registration, saying either would lock Claude and ChatGPT out. The exposure turned out to be a consent screen showing attacker-chosen app names, now handled by trusting redirect hosts.
Publishers:dev.to
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives50
- Confidence50