{"data":{"id":"14f07878-7ac5-4993-99a0-8bb2f6440312","title":"GHSA-6qxp-vccf-f47h: MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server","summary":null,"solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-6qxp-vccf-f47h","publishedAt":"2026-10-06T15:35:44.000Z","cveId":"CVE-2026-104850","cweIds":["CWE-345","CWE-522"],"cvssScore":"7.5","cvssSeverity":"high","severity":"high","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":["@modelcontextprotocol/sdk@>= 1.12.0, < 1.31.0 (fixed: 1.31.0)","@modelcontextprotocol/client@>= 2.0.0, < 2.2.0 (fixed: 2.2.0)"],"affectedPackageNames":["@modelcontextprotocol/sdk","@modelcontextprotocol/client"],"affectedPackageRefs":["npm:@modelcontextprotocol/sdk","npm:@modelcontextprotocol/client"],"affectedVendors":["Anthropic"],"affectedVendorsRaw":["MCP TypeScript SDK","Model Context Protocol"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00176,"epssCheckedAt":"2026-10-10T04:57:18.258Z","kevDateAdded":null,"advisoryAliases":["GHSA-6qxp-vccf-f47h"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2026-10-06T15:35:44.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":["AML.T0010"]}}