
WorkOS pulled three MCP auth bugs into one root cause (Oct 2 writeup): trusting what the other side said. 1) MCP Python SDK GHSA-qx49: client followed attacker token endpoint after discovery fallback (fix 1.30.0/2.2.0 + issuer= for M2M) 2) rmcp CVE-2026-63127: client skipped resource match in protected-resource metadata (fix 2.0.0) 3) LiteLLM CVE-2026-59822: gateway accepted fabricated Bearer into empty auth object (fix 1.84.0, CISA KEV) two directions, same miss: verify on every path, treat missing fields as reject, never substitute a default identity. scanners that only key off CVEs will miss GHSA-qx49. inventory SDKs and gateways, not just CVEs.
