{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/@modelcontextprotocol/client-2.0.0-2.1.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:modelcontextprotocol:sdk:*:*:*:*:*:*:*:*","cpe:2.3:a:modelcontextprotocol:client:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-104850"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@modelcontextprotocol/sdk (1.12.0-1.30.1)","@modelcontextprotocol/client (2.0.0-2.1.0)"],"_cs_severities":["high"],"_cs_tags":["credential-theft","vulnerability","mcp","oauth","cve-2026-104850"],"_cs_type":"advisory","_cs_vendors":["Model Context Protocol"],"content_html":"\u003cp\u003eThe Model Context Protocol (MCP) TypeScript SDK, specifically versions of \u003ccode\u003e@modelcontextprotocol/sdk\u003c/code\u003e (1.12.0 to 1.30.1) and \u003ccode\u003e@modelcontextprotocol/client\u003c/code\u003e (2.0.0 to 2.1.0), contains a high-severity vulnerability (CVE-2026-104850). The vulnerability resides in the OAuth client implementation, which fails to cryptographically bind or validate that the authorization server receiving client credentials is the legitimate issuer.\u003c/p\u003e\n\u003cp\u003eBecause the SDK trusts the MCP server to designate the authorization server endpoint, a malicious or compromised MCP server can redirect authentication traffic to an attacker-controlled server. When the client attempts to authenticate or refresh a token, it inadvertently transmits sensitive data - including \u003ccode\u003erefresh_token\u003c/code\u003e, \u003ccode\u003eclient_secret\u003c/code\u003e, and signed assertions - directly to the attacker. This flaw persists across various connection methods, including \u003ccode\u003ewithOAuth()\u003c/code\u003e middleware and direct \u003ccode\u003efetchToken()\u003c/code\u003e calls, posing a significant risk of credential theft for any client configured to connect to untrusted MCP infrastructure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the complete exfiltration of OAuth credentials and client secrets. If an affected client has previously connected to a malicious MCP server, an attacker can obtain valid refresh tokens, facilitating ongoing unauthorized access to the user's resources on the legitimate authorization server. This vulnerability affects applications using the MCP SDK to facilitate OAuth flows, potentially impacting any organization leveraging the Model Context Protocol to integrate third-party tools that are not strictly internally managed.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003ePatch immediately by upgrading \u003ccode\u003e@modelcontextprotocol/sdk\u003c/code\u003e to 1.31.0 or later, and \u003ccode\u003e@modelcontextprotocol/client\u003c/code\u003e / \u003ccode\u003e@modelcontextprotocol/core\u003c/code\u003e to 2.2.0 or later.\u003c/li\u003e\n\u003cli\u003eAudit existing OAuth integrations for bundled providers; explicitly pass the \u003ccode\u003eexpectedIssuer\u003c/code\u003e parameter to prevent the client from trusting arbitrary endpoints.\u003c/li\u003e\n\u003cli\u003eRotate all \u003ccode\u003eclient_secret\u003c/code\u003e values and signing keys, and revoke any \u003ccode\u003erefresh_tokens\u003c/code\u003e associated with clients that have connected to untrusted MCP servers.\u003c/li\u003e\n\u003cli\u003eManually clear or update persisted tokens stored in file systems, keychains, or databases that lack an associated \u003ccode\u003eissuer\u003c/code\u003e field to ensure they are re-validated upon next use.\u003c/li\u003e\n\u003cli\u003eIf immediate patching is not possible, restrict MCP server connections to trusted, verified endpoints only.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-06T18:48:28Z","date_published":"2026-10-06T18:48:28Z","id":"https://feed.craftedsignal.io/briefs/2026-10-mcp-sdk-oauth-vulnerability/","summary":"The Model Context Protocol (MCP) TypeScript SDK fails to validate authorization server endpoints, allowing malicious MCP servers to intercept refresh tokens and client secrets via credential exfiltration.","title":"Credential Exfiltration Vulnerability in MCP TypeScript SDK OAuth Implementation","url":"https://feed.craftedsignal.io/briefs/2026-10-mcp-sdk-oauth-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - @Modelcontextprotocol/Client (2.0.0-2.1.0)","version":"https://jsonfeed.org/version/1.1"}