MCP TypeScript SDK: OAuth client could leak credentials to servers
A hostile MCP server could redirect an SDK client's stored OAuth secrets to an authorization server it controls.
· Model Context Protocol · Research by Aviral2642, AlexMelanFromRingo, Gal3m, JosephDoUrden, Igfray, OriginalKazdov, lwebmedia
CVE-2026-104850 in the MCP TypeScript SDK let a malicious MCP server pick the authorization server that receives a client's OAuth refresh tokens and client secrets. Fixed in @modelcontextprotocol/sdk 1.31.0 and client 2.2.0.
01What happened
The Model Context Protocol maintainers published a GitHub advisory on September 30, 2026 for the official TypeScript SDK. The SDK's OAuth client did not tie stored credentials to the authorization server that issued them.
02How it works
A malicious or compromised MCP server advertises an authorization server of its choosing. With no user action, the client then sends it the refresh token and client secret saved from an earlier sign-in, or the client secret or signed assertion of a bundled provider. The fix binds credentials to their issuer and makes fetchToken() reject an issuer mismatch.
03Who is affected
Applications built on @modelcontextprotocol/sdk from 1.12.0 up to but not including 1.31.0, and @modelcontextprotocol/client from 2.0.0 up to but not including 2.2.0, that use the OAuth client against MCP servers.
04What to do
Upgrade to @modelcontextprotocol/sdk 1.31.0 or @modelcontextprotocol/client 2.2.0, set expectedIssuer on static credential providers, and rotate refresh tokens and client secrets used against MCP servers you do not trust.
Questions people ask
- Which MCP TypeScript SDK versions fix CVE-2026-104850?
- CVE-2026-104850 is fixed in @modelcontextprotocol/sdk 1.31.0 and in @modelcontextprotocol/client 2.2.0. The GitHub advisory lists sdk versions from 1.12.0 up to but not including 1.31.0, and client versions from 2.0.0 up to but not including 2.2.0, as affected. Projects that pin an older SDK through a lockfile need an explicit upgrade.
- Should I rotate OAuth secrets after the MCP SDK credential leak?
- Rotating secrets is the safe choice after CVE-2026-104850 if your MCP client used OAuth against any MCP server you do not fully trust. The advisory says a malicious server could receive stored refresh tokens and client secrets. Upgrade the MCP SDK first, then rotate refresh tokens and client secrets that those servers could have seen.
- What does expectedIssuer do in the MCP TypeScript SDK?
- The expectedIssuer setting in the MCP TypeScript SDK pins a static credential provider to one authorization server. After the CVE-2026-104850 fix, fetchToken() checks that the issuer matches before sending credentials. The advisory recommends setting expectedIssuer on static credential providers, and leaving it out is now deprecated.
Sources 3 links, all fetched
- 1github.comGitHub Advisory
- 2github.comFix Pull Request
- 3github.comClient 2.2.0 Release