hackwither_

reap / rules / auth and session posture

OAuth redirect URI registration appears overly broad

mcp-redirect-uri-laxity ASI03 Identity and Privilege Abuse severity: medium

What it detects

Overly broad or wildcard OAuth redirect URI registration. ASI03.

Scans discovered OAuth metadata for registered redirect URIs that are wildcarded, non-HTTPS, missing a host, or missing a path.

applies to MCP endpoints

Why it matters

Broad redirect registration enables confused-deputy and code-interception attacks against the agent's identity.

OWASP ASI mapping rationale

Example finding

MEDIUM  mcp-redirect-uri-laxity  MEDIUM CONFIDENCE
OAuth redirect URI registration appears overly broad
The discovered OAuth metadata includes redirect URIs that are broad or wildcarded, which increases the risk of confused-deputy or open redirect abuse.
Evidence  GET /.well-known/oauth-authorization-server → 200

from a scan of reap-range, bad target

Fix

Restrict registered redirect URIs to exact allowed origins and paths, and avoid wildcards or overly permissive URL patterns.

On reap-range

insecure targetbad host well-known (https://evil.example/*) · Medium
correct targetgood host well-known has an exact scoped URI

Run only this check

reap -t https://your-host/mcp --authorized --include mcp-redirect-uri-laxity

Not installed? Install REAP. Only scan systems you own or are authorised to test. Reference: docs/PROBES.md.