Description
There are packages installed that are affected by a vulnerability referenced in the following CVE:
- MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Starting
in version 1.12.0 and prior to versions 1.31.0 and 2.2.0, the SDK's OAuth client support let the MCP
server a client connected to decide which authorization server received the client's OAuth credentials.
Stored and pre-provisioned credentials were not bound to the authorization server they belong to. A
malicious or compromised MCP server could name its own authorization server in its protected resource
metadata. Without any user interaction, the client would send that server the `refresh_token` and
`client_secret` stored from an earlier sign-in (1.x), or the configured `client_secret` or signed
assertion of a bundled non-interactive provider (1.x and 2.x). Only those applications that use the SDK as
an MCP client over HTTP with an `authProvider`: your own `OAuthClientProvider`, or the bundled
`ClientCredentialsProvider`, `PrivateKeyJwtProvider`, `StaticPrivateKeyJwtProvider` or (2.x)
`CrossAppAccessProvider` and that may connect to an MCP server the owners does not fully trust while
holding credentials for a legitimate authorization server are affected. `@modelcontextprotocol/sdk` 1.31.0
(1.x) and `@modelcontextprotocol/client` 2.2.0 (2.x) patch the issue. A workaround for those who cannot
upgrade is available. 2.0.0 and 2.1.0 already accept `expectedIssuer`. On 1.x, the only workaround is to
connect OAuth-enabled clients only to MCP servers you trust. (CVE-2026-104850)
Solution
Update the opensearch-dashboards-2 library and its related packages to version 2.19.6-r25 or later.
Plugin Details
Risk Information
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C
Vulnerability Information
Exploit Ease: No known exploits are available
Vulnerability Publication Date: 10/6/2026