CVE-2026-108586
EUVD-2026-9637310.10.2026, 17:17
1MCP Agent (@1mcp/agent) 0.20.0 through 0.39.0 contains an incorrect authorization vulnerability that allows authenticated clients to bypass OAuth tag-scope enforcement using negated advanced tag-filter expressions. Attackers holding a single-tag token can send a filter like not <granted-tag> to list and invoke tools on backend MCP servers outside their granted scopes.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
References