@angular/cli 21.2.x and 20.3.x depend on @modelcontextprotocol/[email protected] which is vulnerable to CVE-2026-104850
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 1/5
- 预计耗时
- 1 小时以内
- 新手友好度
- 78/100
- Issue 类型
- 缺陷
- 描述清晰度
- 描述清楚
- 活跃度
- 活跃
- 技术栈
- typescript
- 领域
- security
调研方向
在 v21 和 v20 LTS 分支上,定位 packages/angular/cli/package.json(以及 lockfile)中确切的 @modelcontextprotocol/sdk 固定版本,参照 #33789 / #33790 中所做的版本升级。将版本提升到 1.31.0 或更高,刷新 lockfile,并确认 npm audit 不再报告 GHSA-6qxp-vccf-f47h。完成的标准是两个 LTS 分支都能干净安装,且该 CVE 不再有安全公告。
由索引模型根据 Issue 内容生成。
描述
Command
other
Is this a regression?
- Yes, this behavior used to work in the previous version
The previous version in which this bug was not present was
No response
Description
See https://github.com/advisories/GHSA-6qxp-vccf-f47h (CVE-2026-104850, CVSS 7.5): "MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server".
Affected range: @modelcontextprotocol/sdk >= 1.12.0, < 1.31.0 (so 1.30.1 is affected too), patched in 1.31.0.
Both LTS branches pin a vulnerable version exactly (locked on, no update allowed):
- v21 LTS:
@angular/cli21.2.21 through 21.2.25 (latest) depend on@modelcontextprotocol/[email protected](earlier 21.2.x pinned 1.26.0, also affected) - v20 LTS:
@angular/cli20.3.34 through 20.3.38 (latest) depend on@modelcontextprotocol/[email protected](earlier 20.3.x pinned 1.26.0, also affected)
v22 (22.2.x) is not affected, since it depends on @modelcontextprotocol/server instead.
The fix would be bumping @modelcontextprotocol/sdk to 1.31.0 (or later) on both branches, as was done for #33787 (#33789 / #33790).
Minimal Reproduction
- npm install @angular/cli@21 (or @angular/cli@20)
- npm audit
Exception or Error
# npm audit report
@modelcontextprotocol/sdk 1.12.0 - 1.30.1
Severity: high
MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server - https://github.com/advisories/GHSA-6qxp-vccf-f47h
fix available via `npm audit fix --force`
Will install @angular/[email protected], which is a breaking change
node_modules/@modelcontextprotocol/sdk
@angular/cli 20.1.0-next.0 - 22.2.0-rc.0
Depends on vulnerable versions of @modelcontextprotocol/sdk
node_modules/@angular/cli
Your Environment
Angular CLI : 21.2.25 / 20.3.38
Package Manager : npm
Anything else relevant?
No response
- 主要语言
- TypeScript
- 星标
- 27k
- 派生
- 11.8k
- 平均合并
- 1 天 2 分钟
- 30 天内合并 PR
- 168
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
angular/angular-cli 的其他 Issue
-
area: @angular/build gemini-triaged
难度 2/5 1-3 小时 新手友好度 74/100
angular/angular-cli#33955 ·
维护者通常 1 天内回复
-
area: @angular/cli gemini-triaged
难度 2/5 1-3 小时 新手友好度 72/100
angular/angular-cli#33055 · 1 条评论 · 3 个 reaction ·
维护者通常 1 天内回复
-
dev-server: es2016 prebundle target for zone.js apps lowers private fields and breaks dependencies未关闭area: @angular/build
难度 4/5 3-5 天 新手友好度 48/100
angular/angular-cli#34280 ·
维护者通常 1 天内回复
-
area: @angular/build
难度 4/5 3-5 天 新手友好度 48/100
angular/angular-cli#34262 ·
维护者通常 1 天内回复
-
Vite dev server: proxy config normalization reorders glob keys, drops string `context` and misses URLs with a query string可能已有人在做 关联的 PR 仍在进行中或已合并。 未关闭area: @angular/build
难度 4/5 3-5 天 新手友好度 65/100
angular/angular-cli#34257 ·
维护者通常 1 天内回复
查看 angular/angular-cli 的全部 Issue
相似的 Issue
-
[bug] diagnostics.dumpBody:Buffer 形态请求(透传 lane)跳过 dumps/ 落盘,仅留 raw/-unknown-可能已有人在做 @ranxianglei 今天认领。 未关闭
难度 2/5 1-3 小时 新手友好度 62/100
ranxianglei/billion-context#2421 · 2 条评论 ·
维护者通常 1 天内回复
-
pending triage
难度 2/5 1-3 小时 新手友好度 76/100
nuxt/test-utils#1842 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 85/100
MoonshotAI/kimi-code#4146 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 85/100
farbenmeer/tapi#531 ·
-
难度 2/5 1-3 小时 新手友好度 85/100
维护者通常 1 天内回复