gemini-cli patches SSRF flaw in MCP OAuth metadata discovery flows

josebalius · ghdev · 2026-08-25

Google's gemini-cli received a security PR fixing SSRF risks in MCP OAuth metadata discovery, dynamic client registration, and token exchange/refresh flows.

Attack vector: a malicious remote MCP server could use unvalidated WWW-Authenticate challenges or authorizationservers URLs to make the client issue requests to internal IPs, localhost, or cloud metadata services (169.254.169.254).

Key protections:

Original post →

More from coding & agent

coding & agent channel →