PT-2026-106775 · Npm · @Modelcontextprotocol/Sdk+1

CVE-2026-104850

·

Published

2026-10-06

·

Updated

2026-10-07

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions @modelcontextprotocol/sdk versions 1.12.0 through 1.30.1 @modelcontextprotocol/client versions 2.0.0 through 2.1.0
Description The SDK's OAuth client support allows an MCP server to determine which authorization server receives the client's OAuth credentials because stored and pre-provisioned credentials are not bound to their respective authorization servers. A malicious or compromised MCP server could specify its own authorization server in its protected resource metadata. Consequently, without user interaction, the client may send the refresh token and client secret from a previous sign-in, or the client secret or signed assertion of a bundled non-interactive provider. This issue affects applications using the SDK as an MCP client over HTTP with an authProvider (such as a custom OAuthClientProvider or bundled providers like ClientCredentialsProvider, PrivateKeyJwtProvider, StaticPrivateKeyJwtProvider, or CrossAppAccessProvider) that connect to untrusted MCP servers while holding credentials for a legitimate authorization server.
Recommendations Update @modelcontextprotocol/sdk to version 1.31.0 or later. Update @modelcontextprotocol/client to version 2.2.0 or later. For bundled providers (ClientCredentialsProvider, PrivateKeyJwtProvider, StaticPrivateKeyJwtProvider, CrossAppAccessProvider), pass the expectedIssuer parameter to specify the legitimate authorization server. Add the issuer field to credentials persisted in storage (files, keychains, or databases) or clear existing credentials to force a new sign-in. Ensure custom OAuthClientProvider implementations save the issuer provided by saveTokens() and saveClientInformation(), and include the issuer in the return value of clientInformation() for pre-registered credentials. As a temporary workaround for versions 1.x, connect OAuth-enabled clients only to trusted MCP servers. For versions 2.0.0 and 2.1.0, use the expectedIssuer parameter as a mitigation. If a client has connected to an untrusted MCP server, rotate the client secret or signing key and revoke all associated tokens.

Exploit

Fix

Insufficiently Protected Credentials

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-104850
GHSA-6QXP-VCCF-F47H

Affected Products

@Modelcontextprotocol/Client
@Modelcontextprotocol/Sdk