HighVulnerability
GHSA-6qxp-vccf-f47h: MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server
- Identifiers
- CVE-2026-104850GHSA-6qxp-vccf-f47h
- Published
- Record updated
- Affected
- @modelcontextprotocol/sdk >= 1.12.0, < 1.31.0, fixed in 1.31.0
- @modelcontextprotocol/client >= 2.0.0, < 2.2.0, fixed in 2.2.0
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.2%
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- @modelcontextprotocol/clientnpmNo LLM dependency detected · 2 tracked dependents
- @modelcontextprotocol/sdknpmLLM dependency since 2024-11-11 · 18 tracked dependents
Topics
Related items
- HighCVE-2026-101998: Docker Sandboxes fail open when masking credentials in proxy responsesSame vendor · NVD/CVE Database
- HighCVE-2026-103435: Claude Code symlink race condition allows writes outside project directorySame vendor · NVD/CVE Database
- HighCVE-2026-103012: Claude Code stored API key overrides organization policy sign-inSame vendor · NVD/CVE Database
- HighCVE-2026-100585: OpenClaw permission prompt approval bypass through MCP channel bridgeSame vendor · NVD/CVE Database
- MediumGHSA-f26r-j276-ggg4: MCP Atlassian: Arbitrary File Read via Upload Attachment ToolsSame vendor · GitHub Advisory Database