Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

@angular/cli 21.2.x and 20.3.x depend on @modelcontextprotocol/[email protected] which is vulnerable to CVE-2026-104850

已关闭 适合新手
#34,263 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 1 天内回复

还没有人认领这个 Issue。

评估

难度
1/5
预计耗时
1 小时以内
新手友好度
78/100
Issue 类型
缺陷
描述清晰度
描述清楚
活跃度
活跃
技术栈
typescript
领域
security

调研方向

在 v21 和 v20 LTS 分支上,定位 packages/angular/cli/package.json(以及 lockfile)中确切的 @modelcontextprotocol/sdk 固定版本,参照 #33789 / #33790 中所做的版本升级。将版本提升到 1.31.0 或更高,刷新 lockfile,并确认 npm audit 不再报告 GHSA-6qxp-vccf-f47h。完成的标准是两个 LTS 分支都能干净安装,且该 CVE 不再有安全公告。

由索引模型根据 Issue 内容生成。

描述

area: @angular/cli
Command

other

Is this a regression?
  • Yes, this behavior used to work in the previous version
The previous version in which this bug was not present was

No response

Description

See https://github.com/advisories/GHSA-6qxp-vccf-f47h (CVE-2026-104850, CVSS 7.5): "MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server".

Affected range: @modelcontextprotocol/sdk >= 1.12.0, < 1.31.0 (so 1.30.1 is affected too), patched in 1.31.0.

Both LTS branches pin a vulnerable version exactly (locked on, no update allowed):

  • v21 LTS: @angular/cli 21.2.21 through 21.2.25 (latest) depend on @modelcontextprotocol/[email protected] (earlier 21.2.x pinned 1.26.0, also affected)
  • v20 LTS: @angular/cli 20.3.34 through 20.3.38 (latest) depend on @modelcontextprotocol/[email protected] (earlier 20.3.x pinned 1.26.0, also affected)

v22 (22.2.x) is not affected, since it depends on @modelcontextprotocol/server instead.

The fix would be bumping @modelcontextprotocol/sdk to 1.31.0 (or later) on both branches, as was done for #33787 (#33789 / #33790).

Minimal Reproduction
  1. npm install @angular/cli@21 (or @angular/cli@20)
  2. npm audit
Exception or Error
# npm audit report

@modelcontextprotocol/sdk  1.12.0 - 1.30.1
Severity: high
MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server - https://github.com/advisories/GHSA-6qxp-vccf-f47h
fix available via `npm audit fix --force`
Will install @angular/[email protected], which is a breaking change
node_modules/@modelcontextprotocol/sdk
  @angular/cli  20.1.0-next.0 - 22.2.0-rc.0
  Depends on vulnerable versions of @modelcontextprotocol/sdk
  node_modules/@angular/cli
Your Environment
Angular CLI       : 21.2.25 / 20.3.38
Package Manager   : npm
Anything else relevant?

No response

主要语言
TypeScript
星标
27k
派生
11.8k
平均合并
1 天 2 分钟
30 天内合并 PR
168

环境准备

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

angular/angular-cli 的其他 Issue

查看 angular/angular-cli 的全部 Issue

相似的 Issue

更多 TypeScript Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。