Analysis

The Confused Deputy and OAuth Weaknesses in MCP - HACKLIDO - Cybersecurity Blogs, CTF Writeups & Infosec Community

Page published

Publication date unknown · First observed: 9 Oct 2026

Coverage timeline

9 Oct 2026hacklido.comobserved

Single-source analysis — one report is available.

Why it matters

Shared service tokens and confused-deputy design in MCP deployments mean a single successful prompt injection can operate at the privilege of an entire team, making token scope a critical defensive control for agentic systems.

This HACKLIDO blog installment explains the confused-deputy problem and OAuth weaknesses in the Model Context Protocol (MCP), showing how an agent holding a broad shared service token lends that authority to whoever instructs it, including attackers using indirect injection. The piece walks through lab code for a vulnerable 'lookup_customer' MCP tool with no binding to the current ticket owner and discusses token-scoping as the highest-leverage fix.