Skip to content
HighVulnerability

GHSA-6qxp-vccf-f47h: MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server

Published
Record updated
View JSON
Affected
  • @modelcontextprotocol/sdk >= 1.12.0, < 1.31.0, fixed in 1.31.0
  • @modelcontextprotocol/client >= 2.0.0, < 2.2.0, fixed in 2.2.0
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.2%

Mitigation

The source does not state a fix yet. Check the original advisory for updates.