Repository navigation
v0.51.3
Security
Embedded authorization server: upstream callback bound to the initiating browser (GHSA-2gjv-f568-6cxp, High)
/oauth/callback completed a login for whichever browser arrived with a valid upstream state. An attacker who started an authorization for their own client could hand the upstream identity provider URL to a victim and receive an authorization code minted for the victim's identity. The device flow's verification-page login shared the same gap.
Both flows now bind the login to the browser that started it: /oauth/authorize and POST /oauth/device set a per-flow cookie whose hash is stored on the pending record, and the callback completes only when the same browser presents it. The device verification form additionally requires an anti-forgery token, so a cross-site page cannot start a device login from a victim's browser.
What changes for operators and tooling
- Interactive sign-in must be completed in the browser that opened
/oauth/authorizeor the device verification page, with cookies enabled for that host. Headless drivers that walk the flow with a plain HTTP client must carry cookies between steps, and must load the device verification form before posting auser_code. - The upstream callback (
redirect_uri, defaulting to{resourceUrl}/oauth/callbackin the operator) must share a hostname with the browser-facing authorize URL (authorizationEndpointBaseUrl, elseissuer). If the authorize URL ishttps, a non-loopback callback must behttpstoo. Mismatched deployments log aWARNat startup naming the upstream, and every browser login through it is rejected until fixed. - When
authorizationEndpointBaseUrlis set, the device flow'sverification_uriis now advertised from that base URL instead of the issuer. - During a rolling upgrade, a login started on a v0.51.2 replica and finished on v0.51.3 fails within the 10-minute pending window and must be restarted; one started on v0.51.3 and finished on v0.51.2 is not checked.
What's Changed
- Close workflow audit log writers by @kocaemre in #6110
- Preserve vMCP resources until requests drain by @JAORMX in #6715
- Avoid priority annexing unlisted tools by @kocaemre in #6127
- Fix spelling flagged by codespell by @rdimitrov in #6722
- Update docker images by @renovate[bot] in #6719
- Update github actions by @renovate[bot] in #6717
- Update go modules by @renovate[bot] in #6718
- Regenerate OpenAPI docs and SDK for auth config by @rdimitrov in #6724
- Release v0.51.3 by @toolhive-release-app[bot] in #6725
Full Changelog: v0.51.2...v0.51.3