CVE-2026-104850
Received Received - Intake

OAuth Credential Exposure in MCP TypeScript SDK

Vulnerability report for CVE-2026-104850, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Starting in version 1.12.0 and prior to versions 1.31.0 and 2.2.0, the SDK's OAuth client support let the MCP server a client connected to decide which authorization server received the client's OAuth credentials. Stored and pre-provisioned credentials were not bound to the authorization server they belong to. A malicious or compromised MCP server could name its own authorization server in its protected resource metadata. Without any user interaction, the client would send that server the `refresh_token` and `client_secret` stored from an earlier sign-in (1.x), or the configured `client_secret` or signed assertion of a bundled non-interactive provider (1.x and 2.x). Only those applications that use the SDK as an MCP client over HTTP with an `authProvider`: your own `OAuthClientProvider`, or the bundled `ClientCredentialsProvider`, `PrivateKeyJwtProvider`, `StaticPrivateKeyJwtProvider` or (2.x) `CrossAppAccessProvider` and that may connect to an MCP server the owners does not fully trust while holding credentials for a legitimate authorization server are affected. `@modelcontextprotocol/sdk` 1.31.0 (1.x) and `@modelcontextprotocol/client` 2.2.0 (2.x) patch the issue. A workaround for those who cannot upgrade is available. 2.0.0 and 2.1.0 already accept `expectedIssuer`. On 1.x, the only workaround is to connect OAuth-enabled clients only to MCP servers you trust.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
modelcontextprotocol typescript-sdk >= 1.12.0, < 1.31.0
modelcontextprotocol typescript-sdk >= 2.0.0, < 2.2.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-522 The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the MCP TypeScript SDK used for Model Context Protocol servers and clients. It allows a malicious or compromised MCP server to trick clients into sending OAuth credentials to an attacker-controlled authorization server instead of the legitimate one. This happens because stored credentials were not properly bound to their intended authorization server.

Detection Guidance

Detection requires checking if your MCP TypeScript SDK version is between 1.12.0 and 1.30.0 (1.x) or 2.0.0 and 2.1.0 (2.x). Use commands like 'npm list @modelcontextprotocol/sdk' or 'npm list @modelcontextprotocol/client' to verify installed versions.

Impact Analysis

If you use the MCP TypeScript SDK as an MCP client over HTTP with certain auth providers and connect to untrusted MCP servers, your OAuth credentials could be exposed. This includes refresh tokens, client secrets, or signed assertions. Attackers could then impersonate you or gain unauthorized access to your accounts.

Compliance Impact

This vulnerability could lead to unauthorized access to OAuth credentials, potentially violating data protection requirements under GDPR and HIPAA. Exposure of refresh tokens or client secrets may result in unauthorized data access or processing, which conflicts with principles of confidentiality and integrity required by these regulations.

Mitigation Strategies

Upgrade to patched versions: @modelcontextprotocol/sdk 1.31.0 (1.x) or @modelcontextprotocol/client 2.2.0 (2.x). If unable to upgrade, restrict MCP client connections to trusted servers only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104850. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart