Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

GHSA-6qxp-vccf-f47h: add a reference to the related mcp-remote record (CVE-2026-51995)

オープン 初心者向け
#2,946 コメント 4 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
2/5
見積もり時間
1〜3時間
初心者へのやさしさ
72/100
issue の種類
ドキュメント
明瞭さ
おおむね明確
活発さ
活発
技術スタック
typescript

調査の方向性

まず GHSA-6qxp-vccf-f47h のアドバイザリを開き、既存の参照がどのように表示されているかを確認します。関連する参照として CVE-2026-51995 のレコードと mcp-remote F-02 のアドバイザリを追加し、その後、両方のリンクを検証して、findings 間の区別が明確なままであることを確認します。

索引モデルが issue の本文から書いたものです。

説明

v1 v2

Hi, and thanks for fixing GHSA-6qxp-vccf-f47h (CVE-2026-104850).

For readers of that advisory: a related issue on the same trust boundary, a client trusting the authorization server that the MCP server names, was published for mcp-remote, an MCP client built on this SDK, on 31 July 2026, and recorded as CVE-2026-51995 on 24 September 2026. It isn't the same finding: mine is about which authorization server the client goes to during discovery, yours binds credentials to the expected issuer.

I'm not suggesting your fix came from it. The advisory credits its own reporters, and that's right. I'm only asking whether you'd add these as references, so someone reading GHSA-6qxp can find the related client-side record.

Thanks,
Alex Gercog (playb0t)

主要言語
TypeScript
スター
13.5k
フォーク
2.3k
平均マージ
1日 15時間
マージ済み PR(30日)
51

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

modelcontextprotocol/typescript-sdk のほかの issue

modelcontextprotocol/typescript-sdk の issue をすべて見る

似ている issue

TypeScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。