OAuth Vulnerability in Cloudflare MCP Framework Workers
CVE-2025-4144
5.3MEDIUM
What is CVE-2025-4144?
The PKCE (Proof Key for Code Exchange) mechanism, designed to enhance the security of OAuth implementations, has been compromised in the workers-oauth-provider of the MCP framework. An attacker can leverage this vulnerability to bypass the essential PKCE checks, thereby undermining the defenses against certain types of OAuth-related attacks. This flaw highlights the importance of stringent security measures within OAuth 2.1 requirements, as the bypass of PKCE can lead to unauthorized access and potential data breaches.