Vulnerability
Published 2026-09-30
Verified 2026-10-07

MCP TypeScript SDK CVE-2026-104850 (CVSS 7.5): OAuth clients sent stored refresh tokens and client secrets to whichever authorization server a malicious MCP server named; fixed in 1.31.0 and 2.2.0

The Model Context Protocol (MCP) project published advisory GHSA-6qxp-vccf-f47h on 30 September 2026, with CVE-2026-104850 following on 6 October. In affected versions the official TypeScript SDK's OAuth client let the MCP server it connected to decide which authorization server received the client's credentials, because saved credentials were not tied to the authorization server that issued them. A malicious or compromised MCP server could name its own authorization server and, with no user interaction, receive the refresh token and client secret saved from an earlier sign-in, or the client secret or signed assertion configured on a bundled provider. Affected: @modelcontextprotocol/sdk 1.12.0 to 1.30.1, and @modelcontextprotocol/client 2.0.0 and 2.1.0 in specific setups, when the client uses the SDK's OAuth support over HTTP (an authProvider on a transport, the withOAuth() middleware, or direct auth() or fetchToken() calls). MCP servers built with the SDK and stdio clients are not affected. The fix records the issuer on saved credentials and refuses to send them elsewhere, but upgrading is not enough on its own: bundled providers need expectedIssuer set, and credentials saved before the upgrade still go to whichever server is named first unless they gain an issuer or are cleared. A new interactive sign-in still goes where the MCP server points. Primary: MCP GitHub advisory and CVE record.

Product
@modelcontextprotocol/sdk and @modelcontextprotocol/client (official MCP TypeScript SDK, OAuth client)
Versions
@modelcontextprotocol/sdk 1.12.0 to 1.30.1 (fixed 1.31.0); @modelcontextprotocol/client 2.0.0 to 2.1.0 in certain configurations (fixed 2.2.0, with @modelcontextprotocol/core 2.2.0 if imported directly)
CVSS
High (CVSS 3.1)
Exploited in Australia?
unknown
Patch to
Upgrade to @modelcontextprotocol/sdk 1.31.0 or @modelcontextprotocol/client 2.2.0. Then set expectedIssuer on bundled providers (ClientCredentialsProvider, PrivateKeyJwtProvider, StaticPrivateKeyJwtProvider, CrossAppAccessProvider), add the issuer to stored tokens and client information or clear them so users sign in again, and make custom OAuthClientProvider code save the issuer it is given. If an affected client may have connected to an MCP server you do not trust, rotate its client secret or signing key and revoke its tokens. Only complete new sign-ins for MCP servers you trust.

Primary: MCP TypeScript SDK — GHSA-6qxp-vccf-f47h: OAuth client could send credentials to an authorization server chosen by the MCP server (30 Sep 2026) · Vendor: CVE record — CVE-2026-104850 (published 6 Oct 2026) · CVE: CVE-2026-104850

tech ai identity