Skip to content

@angular/cli 21.2.x and 20.3.x depend on @modelcontextprotocol/sdk@1.30.0 which is vulnerable to CVE-2026-104850 #34263

Description

@florimond-collette

Command

other

Is this a regression?

  • Yes, this behavior used to work in the previous version

The previous version in which this bug was not present was

No response

Description

See GHSA-6qxp-vccf-f47h (CVE-2026-104850, CVSS 7.5): "MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server".

Affected range: @modelcontextprotocol/sdk >= 1.12.0, < 1.31.0 (so 1.30.1 is affected too), patched in 1.31.0.

Both LTS branches pin a vulnerable version exactly (locked on, no update allowed):

  • v21 LTS: @angular/cli 21.2.21 through 21.2.25 (latest) depend on @modelcontextprotocol/sdk@1.30.0 (earlier 21.2.x pinned 1.26.0, also affected)
  • v20 LTS: @angular/cli 20.3.34 through 20.3.38 (latest) depend on @modelcontextprotocol/sdk@1.30.0 (earlier 20.3.x pinned 1.26.0, also affected)

v22 (22.2.x) is not affected, since it depends on @modelcontextprotocol/server instead.

The fix would be bumping @modelcontextprotocol/sdk to 1.31.0 (or later) on both branches, as was done for #33787 (#33789 / #33790).

Minimal Reproduction

  1. npm install @angular/cli@21 (or @angular/cli@20)
  2. npm audit

Exception or Error

# npm audit report

@modelcontextprotocol/sdk  1.12.0 - 1.30.1
Severity: high
MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server - https://github.com/advisories/GHSA-6qxp-vccf-f47h
fix available via `npm audit fix --force`
Will install @angular/cli@22.2.1, which is a breaking change
node_modules/@modelcontextprotocol/sdk
  @angular/cli  20.1.0-next.0 - 22.2.0-rc.0
  Depends on vulnerable versions of @modelcontextprotocol/sdk
  node_modules/@angular/cli

Your Environment

Angular CLI       : 21.2.25 / 20.3.38
Package Manager   : npm

Anything else relevant?

No response

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions