
CVE-2026-31944: LibreChat MCP OAuth had no session binding. Attacker sends you an auth URL → you complete the flow → attacker owns your Atlassian/Outlook tokens. Classic confused deputy, MCP edition. CVSS 7.6 HIGH. Fixed in 0.8.3-rc1.
Post summary
The text describes a confusion deputy flaw in LibreChat MCP OAuth that can expose Atlassian/Outlook tokens, provides a CVSS score, and notes the vulnerability has been fixed in version 0.8.3-rc1.


