Pod

Available as Markdown and JSON. Pod is also available over MCP.

Reported issues for OpenGraph.io MCP Server

Pod holds 7 of 7 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.

Back to OpenGraph.io MCP Server.

Most discussed

[Low] CORS reflects any Origin (default *) with Allow-Credentials true and exposes MCP-Session-Id

What's wrong

Live OPTIONS from https://evil.example → ACAO reflects it, credentials true, expose MCP-Session-Id, no Vary. Amplifies High 001.

Where

opengraph-io-mcp + src/server-http.ts:15-31; live mcp.opengraph.io

Blame: BlArcher3127 blake.archer@securecoders.com 0d5951b4d1b1255b05613bf3e6e67764c2a3838c

Fix

Allow-list origins. Stop exposing MCP-Session-Id to arbitrary origins. Add Vary: Origin.

Catalog

Read the thread · 2026-09-16 · open · outside contributor · 0 comments

[Medium] Legacy x-app-id header is an unvalidated identity assertion with no kill switch

What's wrong

Live: any non-empty x-app-id creates a session and bypasses OAuth. Dummy 'test' initialized 200. Intended API-key path, but no format check and no feature flag.

Where

opengraph-io-mcp + src/server-http.ts:91-93; live mcp.opengraph.io

Blame: BlArcher3127 blake.archer@securecoders.com 0d5951b4d1b1255b05613bf3e6e67764c2a3838c

Fix

Validate key format. Add a kill switch for hosted. Prefer OAuth-only on mcp.opengraph.io.

Catalog

Read the thread · 2026-09-16 · open · outside contributor · 0 comments

[Medium] No Express error-handling middleware and NODE_ENV unpinned: stack traces returned to unauthenticated clients

What's wrong

Live 2026-09-16: POST /mcp with malformed JSON returned 400 HTML SyntaxError stack under /app/node_modules/body-parser. Dockerfile has no ENV NODE_ENV=production.

Where

opengraph-io-mcp + src/server-http.ts, Dockerfile; live mcp.opengraph.io

Blame: BlArcher3127 blake.archer@securecoders.com 0d5951b4d1b1255b05613bf3e6e67764c2a3838c

Fix

ENV NODE_ENV=production. Add a terminal error handler that returns a generic 400/500 JSON body.

Catalog

Read the thread · 2026-09-16 · closed · outside contributor · 0 comments

[Medium] Session puzzling: any accepted credential silently rebinds another session's auth context

What's wrong

Live: session created with x-app-id:alpha, then tools/call with x-app-id:beta on that SID → 200. setAuthContext last-write-wins (unlike setAppId which merges).

Where

opengraph-io-mcp + src/server-http.ts:121-122

Blame: BlArcher3127 blake.archer@securecoders.com 0d5951b4d1b1255b05613bf3e6e67764c2a3838c

Fix

Reject identity mismatch. Do not replace an OAuth context with a weaker x-app-id.

Catalog

Read the thread · 2026-09-16 · open · outside contributor · 0 comments

[Medium] GET /mcp and DELETE /mcp perform no authentication at all

What's wrong

Live: GET /mcp with only SID accepted an SSE stream (not 401). DELETE /mcp with only SID returned 200 and evicted the session.

Where

opengraph-io-mcp + src/server-http.ts:159-180; live mcp.opengraph.io

Blame: BlArcher3127 blake.archer@securecoders.com 0d5951b4d1b1255b05613bf3e6e67764c2a3838c

Fix

Call extractAuth on GET and DELETE; 401 if null. Do not treat session ID as a capability.

Catalog

Read the thread · 2026-09-16 · open · outside contributor · 0 comments

[High] Legacy SSE server (src/server.ts) has no authentication, takes the API key in a URL query parameter, and shares one module-global transport — and it is package main / npm start

What's wrong

src/server.ts has no auth, reads app_id from the query string, and uses a single module-global SSEServerTransport. package.json main and npm start point at dist/server.js. README tells operators to npm start and wrongly labels that as the Streamable HTTP server. Hosted mcp.opengraph.io is NOT this file (live /sse and /message are 404; Dockerfile CMD is server-http.js).

Impact

Anyone following the README runs an unauthenticated, cross-session SSE server. Cross-client message…

Read the thread · 2026-09-16 · closed · outside contributor · 0 comments

[High] MCP session ID alone authorizes tool calls: POST /mcp does not reject an unauthenticated or invalid-token request on an established session

What's wrong

On the established-session branch of POST /mcp, extractAuth() is called but a null result is ignored — there is no sendUnauthorized. Possession of MCP-Session-Id is enough. Live 2026-09-16 on mcp.opengraph.io: tools/call getOgData with only mcp-session-id returned 200; a forged Bearer JWT also returned 200. Session IDs are randomUUID() (AC:H) but are exposed via CORS Access-Control-Expose-Headers and land in proxy/HAR logs.

Impact

Stolen/leaked session ID = full use of the…

Read the thread · 2026-09-16 · open · outside contributor · 0 comments

Most recent

The remaining reports are on the project's issue tracker.