Command
other
Is this a regression?
The previous version in which this bug was not present was
No response
Description
See GHSA-6qxp-vccf-f47h (CVE-2026-104850, CVSS 7.5): "MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server".
Affected range: @modelcontextprotocol/sdk >= 1.12.0, < 1.31.0 (so 1.30.1 is affected too), patched in 1.31.0.
Both LTS branches pin a vulnerable version exactly (locked on, no update allowed):
- v21 LTS:
@angular/cli 21.2.21 through 21.2.25 (latest) depend on @modelcontextprotocol/sdk@1.30.0 (earlier 21.2.x pinned 1.26.0, also affected)
- v20 LTS:
@angular/cli 20.3.34 through 20.3.38 (latest) depend on @modelcontextprotocol/sdk@1.30.0 (earlier 20.3.x pinned 1.26.0, also affected)
v22 (22.2.x) is not affected, since it depends on @modelcontextprotocol/server instead.
The fix would be bumping @modelcontextprotocol/sdk to 1.31.0 (or later) on both branches, as was done for #33787 (#33789 / #33790).
Minimal Reproduction
- npm install @angular/cli@21 (or @angular/cli@20)
- npm audit
Exception or Error
# npm audit report
@modelcontextprotocol/sdk 1.12.0 - 1.30.1
Severity: high
MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server - https://github.com/advisories/GHSA-6qxp-vccf-f47h
fix available via `npm audit fix --force`
Will install @angular/cli@22.2.1, which is a breaking change
node_modules/@modelcontextprotocol/sdk
@angular/cli 20.1.0-next.0 - 22.2.0-rc.0
Depends on vulnerable versions of @modelcontextprotocol/sdk
node_modules/@angular/cli
Your Environment
Angular CLI : 21.2.25 / 20.3.38
Package Manager : npm
Anything else relevant?
No response
Command
other
Is this a regression?
The previous version in which this bug was not present was
No response
Description
See GHSA-6qxp-vccf-f47h (CVE-2026-104850, CVSS 7.5): "MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server".
Affected range:
@modelcontextprotocol/sdk >= 1.12.0, < 1.31.0(so 1.30.1 is affected too), patched in1.31.0.Both LTS branches pin a vulnerable version exactly (locked on, no update allowed):
@angular/cli21.2.21 through 21.2.25 (latest) depend on@modelcontextprotocol/sdk@1.30.0(earlier 21.2.x pinned 1.26.0, also affected)@angular/cli20.3.34 through 20.3.38 (latest) depend on@modelcontextprotocol/sdk@1.30.0(earlier 20.3.x pinned 1.26.0, also affected)v22 (22.2.x) is not affected, since it depends on
@modelcontextprotocol/serverinstead.The fix would be bumping
@modelcontextprotocol/sdkto1.31.0(or later) on both branches, as was done for #33787 (#33789 / #33790).Minimal Reproduction
Exception or Error
Your Environment
Anything else relevant?
No response