CVE-2026-104850: MCP TypeScript SDK OAuth could send credentials to a hostile server
GHSA-6qxp-vccf-f47h (CVE-2026-104850, CVSS 7.5) hits @modelcontextprotocol/sdk 1.12.0–1.30.1 and @modelcontextprotocol/client 2.0.0–2.1.0: a malicious MCP server could steer stored refresh tokens, client secrets, or bundled-provider assertions to an attacker-chosen authorization server with no user interaction. Upgrade to sdk 1.31.0 / client 2.2.0, pass expectedIssuer on M2M providers, and clear credentials saved without an issuer.