MCP TypeScript SDK Lets a Malicious Server Pull OAuth Secrets From Clients (CVE-2026-104850)
CVE-2026-104850 lets a malicious MCP server make the TypeScript SDK's OAuth client send refresh tokens and client secrets to an attacker's server. Fixed in 1.31.0 / 2.2.0.