Skip to content

MCPP-CIMD53: Unsafe redirect URI

Family Client ID Metadata Documents
Default severity medium
Confidence high
Mode mcp-posture cimd lint only
Spec revisions 2025-11-25 and later

Why it matters

Authorization codes are delivered to the redirect URI. Plain-http non-loopback, wildcard, fragment or script URIs leak codes; loopback-only documents can be impersonated by any local app, which is why MCP asks authorization servers to warn on them.

Remediation

Use https redirect URIs (or loopback for native apps with PKCE), with exact values, no wildcards and no fragments.

References

Suppressing

# .mcp-posture-ignore
[[ignore]]
check = "MCPP-CIMD53"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31