CVE-2025-4143 describes a critical vulnerability in the OAuth implementation of Cloudflare's workers-oauth-provider, part of the MCP framework. The vulnerability stems from an insufficient validation of the redirect_uri during the initial authorization flow, allowing an attacker to potentially redirect authorized users to malicious sites. This medium-severity vulnerability (CVSS 6.1) has a network attack vector, low complexity, and requires user interaction, potentially leading to credential theft and impersonation if the victim has previously authorized with the server. While there is no evidence of active exploitation or public exploit code, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.0.5CPE matchmatch criteria | cpe:2.3:a:cloudflare:workers-oauth-provider:0.0.5:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.