Answer in brief
CVE-2026-104850 records a High severity (CVSS 7.5) vulnerability in MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server. The current sources do not mark it as known exploited. The current feed maps modelcontextprotocol/typescript-sdk (generic), @modelcontextprotocol/client (npm), @modelcontextprotocol/sdk (npm). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps modelcontextprotocol/typescript-sdk (generic), @modelcontextprotocol/client (npm), @modelcontextprotocol/sdk (npm). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| modelcontextprotocol/typescript-sdkgeneric | >=1.12.0 <1.31.0 || >=2.0.0 <2.2.0 | 1.31.0, 2.2.0 |
| @modelcontextprotocol/clientnpm | >=2.0.0,<2.2.0 | 2.2.0 |
| @modelcontextprotocol/sdknpm | >=1.12.0,<1.31.0 | 1.31.0 |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Starting in version 1.12.0 and prior to versions 1.31.0 and 2.2.0, the SDK's OAuth client support let the MCP server a client connected to decide which authorization server received the client's OAuth credentials. Stored and pre-provisioned credentials were not bound to the authorization server they belong to. A malicious or compromised MCP server could name its own authorization server in its protected resource metadata. Without any user interaction, the client would send that server the `refresh_token` and `client_secret` stored from an earlier sign-in (1.x), or the configured `client_secret` or signed assertion of a bundled non-interactive provider (1.x and 2.x). Only those applications that use the SDK as an MCP client over HTTP with an `authProvider`: your own `OAuthClientProvider`, or the bundled `ClientCredentialsProvider`, `PrivateKeyJwtProvider`, `StaticPrivateKeyJwtProvider` or (2.x) `CrossAppAccessProvider` and that may connect to an MCP server the owners does not fully trust while holding credentials for a legitimate authorization server are affected. `@modelcontextprotocol/sdk` 1.31.0 (1.x) and `@modelcontextprotocol/client` 2.2.0 (2.x) patch the issue. A workaround for those who cannot upgrade is available. 2.0.0 and 2.1.0 already accept `expectedIssuer`. On 1.x, the only workaround is to connect OAuth-enabled clients only to MCP servers you trust.
Quoted source text, attributed separately from HOL analysis.