VYPR
Medium severity5.4NVD Advisory· Published Oct 10, 2026

CVE-2026-108586

CVE-2026-108586

Description

1MCP Agent (@1mcp/agent) 0.20.0 through 0.39.0 contains an incorrect authorization vulnerability that allows authenticated clients to bypass OAuth tag-scope enforcement using negated advanced tag-filter expressions. Attackers holding a single-tag token can send a filter like not to list and invoke tools on backend MCP servers outside their granted scopes.

Affected products

1

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.

CVE-2026-108586 · Medium · VYPR