The Redirect Is Part of the Threat Model: Hardening MCP Client Connections
This story is from 2026-09-14. It is preserved in the archive; the latest stories are on the live feed.
I was reading the release notes for the MCP Python SDK while planning this month’s AAIF Ambassador contribution, and one change stopped me: clients on 2.x now follow HTTP redirects only when they remain within the endpoint’s origin. That’s a good default. A redirect can move a client from the serve…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-09-14 15:50 · DEV Community — AI
The Redirect Is Part of the Threat Model: Hardening MCP Client Connections