@angular/cli 21.2.x and 20.3.x depend on @modelcontextprotocol/[email protected] which is vulnerable to CVE-2026-104850
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 1/5
- Thời gian dự kiến
- Dưới một giờ
- Mức phù hợp với người mới
- 78/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- typescript
- Lĩnh vực
- security
Hướng nghiên cứu
Tìm chính xác điểm ghim @modelcontextprotocol/sdk trong packages/angular/cli/package.json (và lockfile) trên các nhánh LTS v21 và v20, tương tự như thao tác bump đã thực hiện trong #33789 / #33790. Nâng phiên bản lên 1.31.0 trở lên, cập nhật lại lockfile và xác nhận npm audit không còn báo cáo GHSA-6qxp-vccf-f47h. Hoàn thành có nghĩa là cả hai nhánh LTS cài đặt sạch sẽ, không có advisory cho CVE này.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Command
other
Is this a regression?
- Yes, this behavior used to work in the previous version
The previous version in which this bug was not present was
No response
Description
See https://github.com/advisories/GHSA-6qxp-vccf-f47h (CVE-2026-104850, CVSS 7.5): "MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server".
Affected range: @modelcontextprotocol/sdk >= 1.12.0, < 1.31.0 (so 1.30.1 is affected too), patched in 1.31.0.
Both LTS branches pin a vulnerable version exactly (locked on, no update allowed):
- v21 LTS:
@angular/cli21.2.21 through 21.2.25 (latest) depend on@modelcontextprotocol/[email protected](earlier 21.2.x pinned 1.26.0, also affected) - v20 LTS:
@angular/cli20.3.34 through 20.3.38 (latest) depend on@modelcontextprotocol/[email protected](earlier 20.3.x pinned 1.26.0, also affected)
v22 (22.2.x) is not affected, since it depends on @modelcontextprotocol/server instead.
The fix would be bumping @modelcontextprotocol/sdk to 1.31.0 (or later) on both branches, as was done for #33787 (#33789 / #33790).
Minimal Reproduction
- npm install @angular/cli@21 (or @angular/cli@20)
- npm audit
Exception or Error
# npm audit report
@modelcontextprotocol/sdk 1.12.0 - 1.30.1
Severity: high
MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server - https://github.com/advisories/GHSA-6qxp-vccf-f47h
fix available via `npm audit fix --force`
Will install @angular/[email protected], which is a breaking change
node_modules/@modelcontextprotocol/sdk
@angular/cli 20.1.0-next.0 - 22.2.0-rc.0
Depends on vulnerable versions of @modelcontextprotocol/sdk
node_modules/@angular/cli
Your Environment
Angular CLI : 21.2.25 / 20.3.38
Package Manager : npm
Anything else relevant?
No response
- Ngôn ngữ chính
- TypeScript
- Star
- 27k
- Fork
- 11.8k
- Merge trung bình
- 1 ngày 1 giờ
- Pull request đã merge (30 ngày)
- 161
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của angular/angular-cli
-
Can't use an array of hostnames in --allowedHosts cli parameter in @angular/build:dev-serverĐang mởarea: @angular/build gemini-triaged
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 74/100
angular/angular-cli#33955 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
area: @angular/cli gemini-triaged
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
angular/angular-cli#33055 · 1 bình luận · 3 reaction ·
Maintainer thường phản hồi trong vòng 1 ngày
-
SSR resolves relative `redirectTo` against the wrong base when the route path has several segmentsCó thể đã có người làm @bschaeublin đã nhận 1 ngày trước. Đang mởarea: @angular/ssr
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 45/100
angular/angular-cli#34300 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
SSR route redirects drop the query string on relative `redirectTo`Có thể đã có người làm @bschaeublin đã nhận 1 ngày trước. Đang mởarea: @angular/ssr
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 45/100
angular/angular-cli#34298 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
area: @angular/build
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 25/100
angular/angular-cli#34292 ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của angular/angular-cli
Issue tương tự
-
effort:S priority:P2
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
cameri/nostream#811 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 62/100
dam-agents/dam#4562 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug p3 triaged
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
Maintainer thường phản hồi trong vòng 1 ngày
-
bug javascript P2-medium python release:v3.1
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
adrirubio/claude-deck#546 ·
Maintainer thường phản hồi trong vòng 1 ngày