@angular/cli 21.2.x and 20.3.x depend on @modelcontextprotocol/[email protected] which is vulnerable to CVE-2026-104850
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 1/5
- Tiempo estimado
- Menos de una hora
- Aptitud para principiantes
- 78/100
- Tipo de issue
- Error
- Claridad
- Bien especificado
- Estado de actividad
- Activo
- Stack tecnológico
- typescript
- Área
- security
Línea de trabajo
Localiza el pin exacto de @modelcontextprotocol/sdk en packages/angular/cli/package.json (y en el lockfile) en las ramas LTS v21 y v20, replicando el bump hecho en #33789 / #33790. Sube la versión a 1.31.0 o posterior, actualiza el lockfile y confirma que npm audit ya no reporta GHSA-6qxp-vccf-f47h. Hecho significa que ambas ramas LTS se instalan limpiamente sin advisory para este CVE.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Command
other
Is this a regression?
- Yes, this behavior used to work in the previous version
The previous version in which this bug was not present was
No response
Description
See https://github.com/advisories/GHSA-6qxp-vccf-f47h (CVE-2026-104850, CVSS 7.5): "MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server".
Affected range: @modelcontextprotocol/sdk >= 1.12.0, < 1.31.0 (so 1.30.1 is affected too), patched in 1.31.0.
Both LTS branches pin a vulnerable version exactly (locked on, no update allowed):
- v21 LTS:
@angular/cli21.2.21 through 21.2.25 (latest) depend on@modelcontextprotocol/[email protected](earlier 21.2.x pinned 1.26.0, also affected) - v20 LTS:
@angular/cli20.3.34 through 20.3.38 (latest) depend on@modelcontextprotocol/[email protected](earlier 20.3.x pinned 1.26.0, also affected)
v22 (22.2.x) is not affected, since it depends on @modelcontextprotocol/server instead.
The fix would be bumping @modelcontextprotocol/sdk to 1.31.0 (or later) on both branches, as was done for #33787 (#33789 / #33790).
Minimal Reproduction
- npm install @angular/cli@21 (or @angular/cli@20)
- npm audit
Exception or Error
# npm audit report
@modelcontextprotocol/sdk 1.12.0 - 1.30.1
Severity: high
MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server - https://github.com/advisories/GHSA-6qxp-vccf-f47h
fix available via `npm audit fix --force`
Will install @angular/[email protected], which is a breaking change
node_modules/@modelcontextprotocol/sdk
@angular/cli 20.1.0-next.0 - 22.2.0-rc.0
Depends on vulnerable versions of @modelcontextprotocol/sdk
node_modules/@angular/cli
Your Environment
Angular CLI : 21.2.25 / 20.3.38
Package Manager : npm
Anything else relevant?
No response
- Lenguaje dominante
- TypeScript
- Estrellas
- 27k
- Forks
- 11.8k
- Merge medio
- 1 d 1 h
- PR fusionados (30 d)
- 161
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Tiene una plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de angular/angular-cli
-
Can't use an array of hostnames in --allowedHosts cli parameter in @angular/build:dev-serverAbiertoarea: @angular/build gemini-triaged
Dificultad 2/5 1-3 horas Aptitud para principiantes 74/100
angular/angular-cli#33955 ·
Los mantenedores suelen responder en 1 día
-
area: @angular/cli gemini-triaged
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
angular/angular-cli#33055 · 1 comentario · 3 reacciones ·
Los mantenedores suelen responder en 1 día
-
SSR resolves relative `redirectTo` against the wrong base when the route path has several segmentsPosiblemente ocupada @bschaeublin la tomó hace 2 días. Abiertoarea: @angular/ssr
Dificultad 3/5 1-2 días Aptitud para principiantes 45/100
angular/angular-cli#34300 ·
Los mantenedores suelen responder en 1 día
-
SSR route redirects drop the query string on relative `redirectTo`Posiblemente ocupada @bschaeublin la tomó hace 2 días. Abiertoarea: @angular/ssr
Dificultad 3/5 1-2 días Aptitud para principiantes 45/100
angular/angular-cli#34298 ·
Los mantenedores suelen responder en 1 día
-
area: @angular/build
Dificultad 4/5 3-5 días Aptitud para principiantes 25/100
angular/angular-cli#34292 ·
Los mantenedores suelen responder en 1 día
Todos los issues de angular/angular-cli
Issues similares
-
submodule-pointer-regression
Dificultad 1/5 Menos de una hora Aptitud para principiantes 72/100
smith-horn/skillsmith#3061 ·
Los mantenedores suelen responder en 1 día
-
area: ops type: test
Dificultad 2/5 1-3 horas Aptitud para principiantes 79/100
accensa/x402-facilitator-stellar#559 ·
Los mantenedores suelen responder en 1 día
-
Fix the no-pin ruling in line-drawings: pin a below-the-record stage at the record's chapterAbiertodocumentation
Dificultad 2/5 1-3 horas Aptitud para principiantes 74/100
cosimochellini/one-piece-zero-spoiler#551 ·
Los mantenedores suelen responder en 1 día
-
getWatched() omits __proto__ directories when cwd is setPosiblemente ocupada @maxazure la tomó hoy. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 79/100
-
area:web enhancement
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
Los mantenedores suelen responder en 1 día