Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1 advisory

Loading
MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server High
CVE-2026-104850 was published for @modelcontextprotocol/client (npm) Oct 6, 2026
Aviral2642 Credited to Aviral2642, AlexMelanFromRingo, Gal3m, JosephDoUrden, Igfray, OriginalKazdov, and lwebmedia AlexMelanFromRingo AlexMelanFromRingo
Gal3m Gal3m JosephDoUrden JosephDoUrden Igfray Igfray OriginalKazdov OriginalKazdov lwebmedia lwebmedia
ProTip! Advisories are also available from the GraphQL API