OAuth Vulnerability in MCP TypeScript SDK Affecting Model Context Protocol Servers
CVE-2026-104850

7.5HIGH

Key Information:

Vendor
CVE Published:
6 October 2026

What is CVE-2026-104850?

The MCP TypeScript SDK facilitates communication with Model Context Protocol servers and clients. However, versions prior to 1.31.0 and 2.2.0 contain a vulnerability whereby an MCP server can influence the OAuth authorization server that receives client credentials. Malicious entities could potentially compromise the client's OAuth tokens by naming their own authorization server, leading to unauthorized access without user action. Applications utilizing this SDK over HTTP with specific authentication providers are particularly at risk. Users are encouraged to upgrade to the patched versions, or, if upgrading is not feasible, to restrict connections to trusted MCP servers.

Affected Version(s)

typescript-sdk >= 1.12.0, < 1.31.0 < 1.12.0, 1.31.0

typescript-sdk >= 2.0.0, < 2.2.0 < 2.0.0, 2.2.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.