# Reported issues for OpenGraph.io MCP Server

Pod holds 7 of 7 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.

Back to [OpenGraph.io MCP Server](/mcp/opengraph-io-mcp-server).

## Most discussed

### [Low] CORS reflects any Origin (default *) with Allow-Credentials true and exposes MCP-Session-Id

## What's wrong
Live OPTIONS from https://evil.example → ACAO reflects it, credentials true, expose MCP-Session-Id, no Vary. Amplifies High 001.

## Where
opengraph-io-mcp + src/server-http.ts:15-31; live mcp.opengraph.io

Blame: BlArcher3127 <blake.archer@securecoders.com> `0d5951b4d1b1255b05613bf3e6e67764c2a3838c`

## Fix
Allow-list origins. Stop exposing MCP-Session-Id to arbitrary origins. Add Vary: Origin.

## Catalog
- ARAD: `ARAD-OGIOMCP-CORS`
- CWE: CWE-942
- CVSS: 3.7…

[Read the thread](https://github.com/securecoders/opengraph-io-mcp/issues/38) · 2026-09-16 · open · outside contributor · 0 comments

### [Medium] Legacy x-app-id header is an unvalidated identity assertion with no kill switch

## What's wrong
Live: any non-empty x-app-id creates a session and bypasses OAuth. Dummy 'test' initialized 200. Intended API-key path, but no format check and no feature flag.

## Where
opengraph-io-mcp + src/server-http.ts:91-93; live mcp.opengraph.io

Blame: BlArcher3127 <blake.archer@securecoders.com> `0d5951b4d1b1255b05613bf3e6e67764c2a3838c`

## Fix
Validate key format. Add a kill switch for hosted. Prefer OAuth-only on mcp.opengraph.io.

## Catalog
- ARAD: `ARAD-OGIOMCP-XAPPID`
- CWE:…

[Read the thread](https://github.com/securecoders/opengraph-io-mcp/issues/36) · 2026-09-16 · open · outside contributor · 0 comments

### [Medium] No Express error-handling middleware and NODE_ENV unpinned: stack traces returned to unauthenticated clients

## What's wrong
Live 2026-09-16: POST /mcp with malformed JSON returned 400 HTML SyntaxError stack under /app/node_modules/body-parser. Dockerfile has no ENV NODE_ENV=production.

## Where
opengraph-io-mcp + src/server-http.ts, Dockerfile; live mcp.opengraph.io

Blame: BlArcher3127 <blake.archer@securecoders.com> `0d5951b4d1b1255b05613bf3e6e67764c2a3838c`

## Fix
ENV NODE_ENV=production. Add a terminal error handler that returns a generic 400/500 JSON body.

## Catalog
- ARAD:…

[Read the thread](https://github.com/securecoders/opengraph-io-mcp/issues/32) · 2026-09-16 · closed · outside contributor · 0 comments

### [Medium] Session puzzling: any accepted credential silently rebinds another session's auth context

## What's wrong
Live: session created with x-app-id:alpha, then tools/call with x-app-id:beta on that SID → 200. setAuthContext last-write-wins (unlike setAppId which merges).

## Where
opengraph-io-mcp + src/server-http.ts:121-122

Blame: BlArcher3127 <blake.archer@securecoders.com> `0d5951b4d1b1255b05613bf3e6e67764c2a3838c`

## Fix
Reject identity mismatch. Do not replace an OAuth context with a weaker x-app-id.

## Catalog
- ARAD: `ARAD-OGIOMCP-REBIND2`
- CWE: CWE-863
- CVSS: 5.4…

[Read the thread](https://github.com/securecoders/opengraph-io-mcp/issues/29) · 2026-09-16 · open · outside contributor · 0 comments

### [Medium] GET /mcp and DELETE /mcp perform no authentication at all

## What's wrong
Live: GET /mcp with only SID accepted an SSE stream (not 401). DELETE /mcp with only SID returned 200 and evicted the session.

## Where
opengraph-io-mcp + src/server-http.ts:159-180; live mcp.opengraph.io

Blame: BlArcher3127 <blake.archer@securecoders.com> `0d5951b4d1b1255b05613bf3e6e67764c2a3838c`

## Fix
Call extractAuth on GET and DELETE; 401 if null. Do not treat session ID as a capability.

## Catalog
- ARAD: `ARAD-OGIOMCP-GETDEL`
- CWE: CWE-306
- CVSS: 5.3…

[Read the thread](https://github.com/securecoders/opengraph-io-mcp/issues/24) · 2026-09-16 · open · outside contributor · 0 comments

### [High] Legacy SSE server (src/server.ts) has no authentication, takes the API key in a URL query parameter, and shares one module-global transport — and it is package main / npm start

## What's wrong
src/server.ts has no auth, reads app_id from the query string, and uses a single module-global SSEServerTransport. package.json main and npm start point at dist/server.js. README tells operators to npm start and wrongly labels that as the Streamable HTTP server. Hosted mcp.opengraph.io is NOT this file (live /sse and /message are 404; Dockerfile CMD is server-http.js).

## Impact
Anyone following the README runs an unauthenticated, cross-session SSE server. Cross-client message…

[Read the thread](https://github.com/securecoders/opengraph-io-mcp/issues/15) · 2026-09-16 · closed · outside contributor · 0 comments

### [High] MCP session ID alone authorizes tool calls: POST /mcp does not reject an unauthenticated or invalid-token request on an established session

## What's wrong
On the established-session branch of POST /mcp, extractAuth() is called but a null result is ignored — there is no sendUnauthorized. Possession of MCP-Session-Id is enough. Live 2026-09-16 on mcp.opengraph.io: tools/call getOgData with only mcp-session-id returned 200; a forged Bearer JWT also returned 200. Session IDs are randomUUID() (AC:H) but are exposed via CORS Access-Control-Expose-Headers and land in proxy/HAR logs.

## Impact
Stolen/leaked session ID = full use of the…

[Read the thread](https://github.com/securecoders/opengraph-io-mcp/issues/14) · 2026-09-16 · open · outside contributor · 0 comments

## Most recent

The remaining reports are on [the project's issue tracker](https://github.com/securecoders/opengraph-io-mcp/issues).
