CVE-2026-108586: 1mcp-App @1mcp/agent
Medium severity, CVSS 5.4.
1MCP Agent (@1mcp/agent) 0.20.0 through 0.39.0 contains an incorrect authorization vulnerability that allows authenticated clients to bypass OAuth tag-scope enforcement using negated advanced tag-filter expressions. Attackers holding a single-tag token can send a filter like not <granted-tag> to list and invoke tools on backend MCP servers outside their granted scopes.
Affected products
- 1mcp-App @1mcp/agent: from 0.20.0, up to and including 0.39.0
Published 2026-10-10. Last modified 2026-10-10.