Description
MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Starting in version 1.12.0 and prior to versions 1.31.0 and 2.2.0, the SDK's OAuth client support let the MCP server a client connected to decide which authorization server received the client's OAuth credentials. Stored and pre-provisioned credentials were not bound to the authorization server they belong to. A malicious or compromised MCP server could name its own authorization server in its protected resource metadata. Without any user interaction, the client would send that server the `refresh_token` and `client_secret` stored from an earlier sign-in (1.x), or the configured `client_secret` or signed assertion of a bundled non-interactive provider (1.x and 2.x). Only those applications that use the SDK as an MCP client over HTTP with an `authProvider`: your own `OAuthClientProvider`, or the bundled `ClientCredentialsProvider`, `PrivateKeyJwtProvider`, `StaticPrivateKeyJwtProvider` or (2.x) `CrossAppAccessProvider` and that may connect to an MCP server the owners does not fully trust while holding credentials for a legitimate authorization server are affected. `@modelcontextprotocol/sdk` 1.31.0 (1.x) and `@modelcontextprotocol/client` 2.2.0 (2.x) patch the issue. A workaround for those who cannot upgrade is available. 2.0.0 and 2.1.0 already accept `expectedIssuer`. On 1.x, the only workaround is to connect OAuth-enabled clients only to MCP servers you trust.
Published: 2026-10-06
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Credential Theft via Authority Injection
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from the fact that the SDK’s OAuth client does not bind stored or pre‑provisioned credentials to a specific authorization server. As a result, a malicious or compromised MCP server can advertise its own authorization server in resource metadata, causing a client to silently send its refresh_token, client_secret, or signed assertion to that injected server. This enables credential theft and establishes unauthorized access to protected resources. The weakness is an absence of authorization server binding (CWE‑345)CWE‑522).

Affected Systems

Model Context Protocol’s TypeScript SDK – the package published under @modelcontextprotocol/sdk for the 1.x line and @modelcontextprotocol/client for 2.x – is affected. Versions starting at 1.12.0 and up through the release just before 1.31.0, as well as the 2.x releases up until before 2.2.0, contain the flaw. Versions 1.31.0 and 2.2.0 contain the upstream fix. Earlier 2.0.0 and 2.1.0 releases provide an expectedIssuer check that reduces the impact but do not fully eliminate the risk without the full patch.

Risk and Exploitability

The reported CVSS score of 7.5 indicates moderate to high potential impact. Exploitability is enabled by a compromised MCP server; no user interaction or special privileges on the client side are required. EPSS data is unavailable, and the vulnerability is not listed in CISA KEV, meaning there is no known widespread exploitation yet, but the underlying weakness is significant enough that an attacker with control over the MCP server could obtain client credentials and impersonate legitimate clients. Organizations using the SDK should consider the upgrade urgent to prevent potential credential compromise.

Generated by OpenCVE AI on October 6, 2026 at 18:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade @modelcontextprotocol/sdk to version 1.31.0 or later or @modelcontextprotocol/client to version 2.2.0 or later, which contain the official fix.
  • If available, enable the expectedIssuer validation on the client side (versions 2.0.0 and 2.1.0 provide this check) to reduce the risk until the full patch is applied.
  • When an upgrade is not immediately possible, restrict OAuth-enabled clients to MCP servers that are fully trusted and monitor for any unexpected authorization server redirection.

Generated by OpenCVE AI on October 6, 2026 at 18:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-6qxp-vccf-f47h MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server
History

Tue, 06 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Description MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Starting in version 1.12.0 and prior to versions 1.31.0 and 2.2.0, the SDK's OAuth client support let the MCP server a client connected to decide which authorization server received the client's OAuth credentials. Stored and pre-provisioned credentials were not bound to the authorization server they belong to. A malicious or compromised MCP server could name its own authorization server in its protected resource metadata. Without any user interaction, the client would send that server the `refresh_token` and `client_secret` stored from an earlier sign-in (1.x), or the configured `client_secret` or signed assertion of a bundled non-interactive provider (1.x and 2.x). Only those applications that use the SDK as an MCP client over HTTP with an `authProvider`: your own `OAuthClientProvider`, or the bundled `ClientCredentialsProvider`, `PrivateKeyJwtProvider`, `StaticPrivateKeyJwtProvider` or (2.x) `CrossAppAccessProvider` and that may connect to an MCP server the owners does not fully trust while holding credentials for a legitimate authorization server are affected. `@modelcontextprotocol/sdk` 1.31.0 (1.x) and `@modelcontextprotocol/client` 2.2.0 (2.x) patch the issue. A workaround for those who cannot upgrade is available. 2.0.0 and 2.1.0 already accept `expectedIssuer`. On 1.x, the only workaround is to connect OAuth-enabled clients only to MCP servers you trust.
Title MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server
Weaknesses CWE-345
CWE-522
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T16:28:53.097Z

Reserved: 2026-10-02T14:38:43.244Z

Link: CVE-2026-104850

cve-icon Vulnrichment

Updated: 2026-10-06T16:28:48.282Z

cve-icon NVD

Status : Received

Published: 2026-10-06T17:17:15.827

Modified: 2026-10-06T17:17:15.827

Link: CVE-2026-104850

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T18:15:04Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity

  • CWE-522

    Insufficiently Protected Credentials