Skip to content

MCP OAuth Consent-Layer Confused Deputy via Open Dynamic Client Registration

mcp-oauth-consent-dcr-abuse is a high severity check in the ai category, written in python. Its source is templates/ai/mcp/mcp-oauth-consent-dcr-abuse.py in cert-x-gen-templates.

ACTIVE check. Drives an MCP OAuth authorization server through open Dynamic Client Registration and observes, by behaviour, whether an attacker-registered redirect_uri receives an authorization code with NO re-consent - the consent-layer confused deputy. Distinct from token-audience and issuer-binding: this tests the consent + registration layer, not the token. Also checks RFC 9207 iss return and state binding.

Field Value
Id mcp-oauth-consent-dcr-abuse
Severity high
Language python
Category ai
Author Bugb Research
Template version 1.0.0
Confidence 90
CVSS 8.2
Weakness CWE-441, CWE-601
Tags mcp, ai, agent, oauth, oauth-conformance, dynamic-client-registration, dcr, consent, confused-deputy, redirect-uri, rfc9207, rfc7591, authorization-server, behavioural, active, intrusive, cwe-441, cwe-601
Target kind http
Oracle property

Declared in the header. cxg parses @references and then discards it, and nothing at scan time reads it, so this is the only place the links a template cites are surfaced.

To see what the copy on your machine says about itself, and to confirm it is installed at all:

Terminal window
cxg template info mcp-oauth-consent-dcr-abuse

The id it prints is the one to pass anywhere a template is selected. See cxg template for the rest of the subcommand, Scan a target for running a scan, and A match is not a finding for how to read what comes back.