<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-2026-104850 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-104850/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 06 Oct 2026 18:48:28 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-104850/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Credential Exfiltration Vulnerability in MCP TypeScript SDK OAuth Implementation</title><link>https://feed.craftedsignal.io/briefs/2026-10-mcp-sdk-oauth-vulnerability/</link><pubDate>Tue, 06 Oct 2026 18:48:28 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-mcp-sdk-oauth-vulnerability/</guid><description>The Model Context Protocol (MCP) TypeScript SDK fails to validate authorization server endpoints, allowing malicious MCP servers to intercept refresh tokens and client secrets via credential exfiltration.</description><content:encoded><![CDATA[<p>The Model Context Protocol (MCP) TypeScript SDK, specifically versions of <code>@modelcontextprotocol/sdk</code> (1.12.0 to 1.30.1) and <code>@modelcontextprotocol/client</code> (2.0.0 to 2.1.0), contains a high-severity vulnerability (CVE-2026-104850). The vulnerability resides in the OAuth client implementation, which fails to cryptographically bind or validate that the authorization server receiving client credentials is the legitimate issuer.</p>
<p>Because the SDK trusts the MCP server to designate the authorization server endpoint, a malicious or compromised MCP server can redirect authentication traffic to an attacker-controlled server. When the client attempts to authenticate or refresh a token, it inadvertently transmits sensitive data - including <code>refresh_token</code>, <code>client_secret</code>, and signed assertions - directly to the attacker. This flaw persists across various connection methods, including <code>withOAuth()</code> middleware and direct <code>fetchToken()</code> calls, posing a significant risk of credential theft for any client configured to connect to untrusted MCP infrastructure.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for the complete exfiltration of OAuth credentials and client secrets. If an affected client has previously connected to a malicious MCP server, an attacker can obtain valid refresh tokens, facilitating ongoing unauthorized access to the user's resources on the legitimate authorization server. This vulnerability affects applications using the MCP SDK to facilitate OAuth flows, potentially impacting any organization leveraging the Model Context Protocol to integrate third-party tools that are not strictly internally managed.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Patch immediately by upgrading <code>@modelcontextprotocol/sdk</code> to 1.31.0 or later, and <code>@modelcontextprotocol/client</code> / <code>@modelcontextprotocol/core</code> to 2.2.0 or later.</li>
<li>Audit existing OAuth integrations for bundled providers; explicitly pass the <code>expectedIssuer</code> parameter to prevent the client from trusting arbitrary endpoints.</li>
<li>Rotate all <code>client_secret</code> values and signing keys, and revoke any <code>refresh_tokens</code> associated with clients that have connected to untrusted MCP servers.</li>
<li>Manually clear or update persisted tokens stored in file systems, keychains, or databases that lack an associated <code>issuer</code> field to ensure they are re-validated upon next use.</li>
<li>If immediate patching is not possible, restrict MCP server connections to trusted, verified endpoints only.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>credential-theft</category><category>vulnerability</category><category>mcp</category><category>oauth</category><category>cve-2026-104850</category></item></channel></rss>