Executive brief
Cloudflare's workers-oauth-provider is a library used to implement OAuth 2.1 authentication in MCP servers. An attacker can downgrade the authentication mechanism to bypass PKCE (Proof Key for Code Exchange), a security control that protects against certain authorization code interception attacks. This allows an attacker with network access to hijack user authentication flows without the victim knowing.
Technical details
The vulnerability is an authentication bypass in the PKCE validation logic of the workers-oauth-provider library. PKCE, a defense-in-depth mechanism originally optional in OAuth 2.0 and now required by OAuth 2.1, can be completely bypassed through a downgrade attack where an attacker causes the PKCE check to be skipped. The vulnerability affects all versions prior to 0.0.5 and is remotely exploitable with no privileges or special attack requirements, only requiring passive user interaction. An attacker can exploit this to obtain OAuth tokens without proper PKCE validation, potentially allowing account takeover. The fix is available in version 0.0.5 of @cloudflare/workers-oauth-provider.
Affected products
- Cloudflare workers-oauth-provider < 0.0.5
Timeline
- 2025-05-01: disclosed
- 2025-05-01: patched: Fixed in version 0.0.5