Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

@angular/cli 21.2.x and 20.3.x depend on @modelcontextprotocol/[email protected] which is vulnerable to CVE-2026-104850

Đã đóng Phù hợp với người mới
#34,263 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
1/5
Thời gian dự kiến
Dưới một giờ
Mức phù hợp với người mới
78/100
Loại issue
Lỗi
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
typescript
Lĩnh vực
security

Hướng nghiên cứu

Tìm chính xác điểm ghim @modelcontextprotocol/sdk trong packages/angular/cli/package.json (và lockfile) trên các nhánh LTS v21 và v20, tương tự như thao tác bump đã thực hiện trong #33789 / #33790. Nâng phiên bản lên 1.31.0 trở lên, cập nhật lại lockfile và xác nhận npm audit không còn báo cáo GHSA-6qxp-vccf-f47h. Hoàn thành có nghĩa là cả hai nhánh LTS cài đặt sạch sẽ, không có advisory cho CVE này.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

area: @angular/cli
Command

other

Is this a regression?
  • Yes, this behavior used to work in the previous version
The previous version in which this bug was not present was

No response

Description

See https://github.com/advisories/GHSA-6qxp-vccf-f47h (CVE-2026-104850, CVSS 7.5): "MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server".

Affected range: @modelcontextprotocol/sdk >= 1.12.0, < 1.31.0 (so 1.30.1 is affected too), patched in 1.31.0.

Both LTS branches pin a vulnerable version exactly (locked on, no update allowed):

  • v21 LTS: @angular/cli 21.2.21 through 21.2.25 (latest) depend on @modelcontextprotocol/[email protected] (earlier 21.2.x pinned 1.26.0, also affected)
  • v20 LTS: @angular/cli 20.3.34 through 20.3.38 (latest) depend on @modelcontextprotocol/[email protected] (earlier 20.3.x pinned 1.26.0, also affected)

v22 (22.2.x) is not affected, since it depends on @modelcontextprotocol/server instead.

The fix would be bumping @modelcontextprotocol/sdk to 1.31.0 (or later) on both branches, as was done for #33787 (#33789 / #33790).

Minimal Reproduction
  1. npm install @angular/cli@21 (or @angular/cli@20)
  2. npm audit
Exception or Error
# npm audit report

@modelcontextprotocol/sdk  1.12.0 - 1.30.1
Severity: high
MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server - https://github.com/advisories/GHSA-6qxp-vccf-f47h
fix available via `npm audit fix --force`
Will install @angular/[email protected], which is a breaking change
node_modules/@modelcontextprotocol/sdk
  @angular/cli  20.1.0-next.0 - 22.2.0-rc.0
  Depends on vulnerable versions of @modelcontextprotocol/sdk
  node_modules/@angular/cli
Your Environment
Angular CLI       : 21.2.25 / 20.3.38
Package Manager   : npm
Anything else relevant?

No response

Ngôn ngữ chính
TypeScript
Star
27k
Fork
11.8k
Merge trung bình
1 ngày 1 giờ
Pull request đã merge (30 ngày)
161

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của angular/angular-cli

Tất cả issue của angular/angular-cli

Issue tương tự

Thêm issue về TypeScript

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.