Threat Advisory

MCP TypeScript SDK OAuth Client Sends Credentials to Unauthorized Server

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A high-severity vulnerability affecting @modelcontextprotocol/sdk versions providers that read storage back through `OAuthTokensSchema` or `OAuthClientInformationSchema` affecting @modelcontextprotocol/sdk versions 1.x: `@modelcontextprotocol/sdk` 1.31.0 or later (CVE-2026-104850, CVSS score: 7.5) affects MCP TypeScript SDK OAuth clients in versions >= 1.12.0, < 1.31.0 and @modelcontextprotocol/client versions >= 2.0.0, < 2.2.0, allowing a malicious or compromised MCP server to obtain client credentials by naming its own authorization server. This flaw type is a CWE-345 and CWE-522 issue, where credentials are not tied to the authorization server they belong to. The business impact of this vulnerability is significant, as an attacker could use the stolen credentials to access sensitive information or perform unauthorized actions. Affected versions include @modelcontextprotocol/sdk 1.12.0 through 1.30.1 and @modelcontextprotocol/client 2.0.0 through 2.1.0 for bundled providers without expectedIssuer or credentials stored or supplied without issuer.

RECOMMENDATION:

We recommend you to update @modelcontextprotocol/sdk to version 1.31.0.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A high-severity vulnerability affecting @modelcontextprotocol/sdk versions providers that read storage back through `OAuthTokensSchema` or `OAuthClientInformationSchema` affecting @modelcontextprotocol/sdk versions 1.x: `@modelcontextprotocol/sdk` 1.31.0 or later (CVE-2026-104850, CVSS score: 7.5) affects MCP TypeScript SDK OAuth clients in versions >= 1.12.0, < 1.31.0 and @modelcontextprotocol/client versions >= 2.0.0, < 2.2.0, allowing a malicious or compromised MCP server to obtain client credentials by naming its own authorization server. This flaw type is a CWE-345 and CWE-522 issue, where credentials are not tied to the authorization server they belong to. The business impact of this vulnerability is significant, as an attacker could use the stolen credentials to access sensitive information or perform unauthorized actions. Affected versions include @modelcontextprotocol/sdk 1.12.0 through 1.30.1 and @modelcontextprotocol/client 2.0.0 through 2.1.0 for bundled providers without expectedIssuer or credentials stored or supplied without issuer.

RECOMMENDATION:

We recommend you to update @modelcontextprotocol/sdk to version 1.31.0.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu