Skip to content
Threat Feed
high advisory

Credential Exfiltration Vulnerability in MCP TypeScript SDK OAuth Implementation

The Model Context Protocol (MCP) TypeScript SDK fails to validate authorization server endpoints, allowing malicious MCP servers to intercept refresh tokens and client secrets via credential exfiltration.

CVE search metadata

CVE search record: CVE-2026-104850. Severity: high. CVSS: 7.5. KEV: no. Product: @modelcontextprotocol/sdk (1.12.0-1.30.1), @modelcontextprotocol/client (2.0.0-2.1.0). Brief: Credential Exfiltration Vulnerability in MCP TypeScript SDK OAuth Implementation. Brief link: https://feed.craftedsignal.io/briefs/2026-10-mcp-sdk-oauth-vulnerability/

The Model Context Protocol (MCP) TypeScript SDK, specifically versions of @modelcontextprotocol/sdk (1.12.0 to 1.30.1) and @modelcontextprotocol/client (2.0.0 to 2.1.0), contains a high-severity vulnerability (CVE-2026-104850). The vulnerability resides in the OAuth client implementation, which fails to cryptographically bind or validate that the authorization server receiving client credentials is the legitimate issuer.

Because the SDK trusts the MCP server to designate the authorization server endpoint, a malicious or compromised MCP server can redirect authentication traffic to an attacker-controlled server. When the client attempts to authenticate or refresh a token, it inadvertently transmits sensitive data - including refresh_token, client_secret, and signed assertions - directly to the attacker. This flaw persists across various connection methods, including withOAuth() middleware and direct fetchToken() calls, posing a significant risk of credential theft for any client configured to connect to untrusted MCP infrastructure.

Impact

Successful exploitation allows for the complete exfiltration of OAuth credentials and client secrets. If an affected client has previously connected to a malicious MCP server, an attacker can obtain valid refresh tokens, facilitating ongoing unauthorized access to the user's resources on the legitimate authorization server. This vulnerability affects applications using the MCP SDK to facilitate OAuth flows, potentially impacting any organization leveraging the Model Context Protocol to integrate third-party tools that are not strictly internally managed.

Recommendation

  1. Patch immediately by upgrading @modelcontextprotocol/sdk to 1.31.0 or later, and @modelcontextprotocol/client / @modelcontextprotocol/core to 2.2.0 or later.
  2. Audit existing OAuth integrations for bundled providers; explicitly pass the expectedIssuer parameter to prevent the client from trusting arbitrary endpoints.
  3. Rotate all client_secret values and signing keys, and revoke any refresh_tokens associated with clients that have connected to untrusted MCP servers.
  4. Manually clear or update persisted tokens stored in file systems, keychains, or databases that lack an associated issuer field to ensure they are re-validated upon next use.
  5. If immediate patching is not possible, restrict MCP server connections to trusted, verified endpoints only.

Immediate actions

Upgrade @modelcontextprotocol packages to the patched versions identified in the brief.

IT Operations 24h

Rotate all secrets and revoke tokens for clients potentially exposed to untrusted MCP servers.

SOC 48h

Mitigations

Enforce `expectedIssuer` for all bundled providers in client configurations.

immediate IT Operations

CVE-2026-104850