CVE WATCH / VULNERABILITY DETAIL
CVE-2026-104850
HIGHCVSS 7.5NVD feed
Published 6 October 2026 · tracked since 7 October 2026
Description
MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Starting in version 1.12.0 and prior to versions 1.31.0 and 2.2.0, the SDK's OAuth client support let the MCP server a client connected to decide which authorization server received the client's OAuth c
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-106241 CRITICAL 9.6
- CVE-2026-106233 HIGH 8.3
- CVE-2026-106234 CRITICAL 9.6
- CVE-2026-106235 HIGH 8.8
- CVE-2026-106238 HIGH 8.3
- CVE-2026-106239 CRITICAL 9.6
- CVE-2026-106240 HIGH 8.8
- CVE-2026-106225 HIGH 8.8
- CVE-2026-106227 CRITICAL 9.6
- CVE-2026-106228 HIGH 8.3