Analysis
The Confused Deputy and OAuth Weaknesses in MCP - HACKLIDO - Cybersecurity Blogs, CTF Writeups & Infosec Community
Publication date unknown · Discovered hacklido.com
Page published
Publication date unknown · First observed: 9 Oct 2026
Coverage timeline
Single-source analysis — one report is available.
Why it matters
Shared service tokens and confused-deputy design in MCP deployments mean a single successful prompt injection can operate at the privilege of an entire team, making token scope a critical defensive control for agentic systems.
This HACKLIDO blog installment explains the confused-deputy problem and OAuth weaknesses in the Model Context Protocol (MCP), showing how an agent holding a broad shared service token lends that authority to whoever instructs it, including attackers using indirect injection. The piece walks through lab code for a vulnerable 'lookup_customer' MCP tool with no binding to the current ticket owner and discusses token-scoping as the highest-leverage fix.