Impact
The vulnerability arises from the fact that the SDK’s OAuth client does not bind stored or pre‑provisioned credentials to a specific authorization server. As a result, a malicious or compromised MCP server can advertise its own authorization server in resource metadata, causing a client to silently send its refresh_token, client_secret, or signed assertion to that injected server. This enables credential theft and establishes unauthorized access to protected resources. The weakness is an absence of authorization server binding (CWE‑345)CWE‑522).
Affected Systems
Model Context Protocol’s TypeScript SDK – the package published under @modelcontextprotocol/sdk for the 1.x line and @modelcontextprotocol/client for 2.x – is affected. Versions starting at 1.12.0 and up through the release just before 1.31.0, as well as the 2.x releases up until before 2.2.0, contain the flaw. Versions 1.31.0 and 2.2.0 contain the upstream fix. Earlier 2.0.0 and 2.1.0 releases provide an expectedIssuer check that reduces the impact but do not fully eliminate the risk without the full patch.
Risk and Exploitability
The reported CVSS score of 7.5 indicates moderate to high potential impact. Exploitability is enabled by a compromised MCP server; no user interaction or special privileges on the client side are required. EPSS data is unavailable, and the vulnerability is not listed in CISA KEV, meaning there is no known widespread exploitation yet, but the underlying weakness is significant enough that an attacker with control over the MCP server could obtain client credentials and impersonate legitimate clients. Organizations using the SDK should consider the upgrade urgent to prevent potential credential compromise.
OpenCVE Enrichment
Github GHSA