Repository navigation
fix(deps): update dependency @modelcontextprotocol/sdk to v1.31.0 [security] - #1974
renovate[bot] wants to merge 1 commit into
Conversation
|
Important Review skippedAuto reviews are limited based on label configuration. 🏷️ Required labels (at least one) (1)
Please check the settings in the CodeRabbit UI or the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
Review statusThis PR was opened by an automated account. A human maintainer must verify the change intent, provenance, and validation before merging. Current step: Awaiting fresh human maintainer or CODEOWNER approval. Review-state labels are managed by this workflow; do not edit them manually. |
This PR contains the following updates:
1.29.0→1.31.0MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server
CVE-2026-104850 / GHSA-6qxp-vccf-f47h
More information
Details
Summary
In affected versions, the SDK's OAuth client let the MCP server decide which authorization server received the client's OAuth credentials. Credentials were not tied to the authorization server they belong to.
A malicious or compromised MCP server could name its own authorization server. With no user interaction, the client would send it:
refresh_tokenandclient_secretstored from an earlier sign-inclient_secretor signed assertion configured on a bundled providerAm I affected?
Yes, if both of these hold:
authProvideron a transportwithOAuth()middlewareauth()orfetchToken()Affected versions:
@modelcontextprotocol/sdk1.12.0 through 1.30.1@modelcontextprotocol/client2.0.0 through 2.1.0, only for:expectedIssuerissuerfetchToken()OAuthTokensSchemaorOAuthClientInformationSchemaNot affected:
Fix
Upgrade to:
@modelcontextprotocol/sdk1.31.0 or later@modelcontextprotocol/client2.2.0 or later, and@modelcontextprotocol/core2.2.0 or later if you import it directlyThe client now records the authorization server as
issueron saved credentials and does not send them to a different one. The user signs in again, or the call throws.In the following cases, upgrading to the patched version is not enough. You also need to make a change:
ClientCredentialsProvider,PrivateKeyJwtProvider,StaticPrivateKeyJwtProvider,CrossAppAccessProvider): passexpectedIssuer, for exampleexpectedIssuer: 'https://auth.example.com'. Without it they still use whichever authorization server the MCP server names.issuer: tokens and client information yourOAuthClientProviderpersisted (file, keychain, database) before upgrading, including everything 1.x saved before 1.31.0. They still go to whichever authorization server is named at first use. Addissuerto them, or clear them so users sign in again.OAuthClientProvider: save exactly whatsaveTokens()andsaveClientInformation()are given, includingissuer. For pre-registered credentials, includeissuerin whatclientInformation()returns.Not covered by this fix:
refreshAuthorization()andexchangeAuthorization()called directlyskipIssuerMetadataValidation: trueIf an affected client may have connected to an untrusted MCP server, rotate its client secret or signing key and revoke its tokens.
If you cannot upgrade yet, connect OAuth clients only to MCP servers you trust. 2.0.0 and 2.1.0 already accept
expectedIssuer.Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
modelcontextprotocol/typescript-sdk (@modelcontextprotocol/sdk)
v1.31.0Compare Source
Upgrade notes
issuerfield. Storage that rejects unknown fields needs to allow it.expectedIssuerwhen constructingClientCredentialsProvider,PrivateKeyJwtProviderorStaticPrivateKeyJwtProvider. Constructing them without it is deprecated.What's Changed
Full Changelog: modelcontextprotocol/typescript-sdk@1.30.1...1.31.0
v1.30.1Compare Source
What's Changed
New Contributors
Full Changelog: modelcontextprotocol/typescript-sdk@1.30.0...1.30.1
v1.30.0Compare Source
What's Changed
New Contributors
Full Changelog: modelcontextprotocol/typescript-sdk@v1.29.0...1.30.0
Configuration
📅 Schedule: (in timezone America/Los_Angeles)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.