Skip to content

chore: upgrade @modelcontextprotocol/sdk to ^1.32.1 to address CVE-2026-104850 - #1719

Merged
brendan-kellam merged 2 commits into
mainfrom
cursor/cve/modelcontextprotocol-sdk
Oct 9, 2026
Merged

brendan-kellam merged 2 commits into
mainfrom
cursor/cve/modelcontextprotocol-sdk

Conversation

@claude

@claude claude Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Fixes SOU-2526

Addresses CVE-2026-104850 (Dependabot alert #399). The MCP TypeScript SDK OAuth client could send credentials to an authorization server chosen by the MCP server. Affects @modelcontextprotocol/sdk 1.12.0 through 1.30.1, patched in 1.31.0.

The lockfile was stale. Both existing ranges (^1.29.0 from @sourcebot/web and ^1.25.0 from @react-grab/mcp) already admit the patched version, so this is a lockfile refresh via yarn up -R @modelcontextprotocol/sdk. No package.json change and no resolutions override. Both requesters now resolve to 1.32.1 (previously 1.29.0 and 1.27.1).

Note: Sourcebot uses the SDK's server APIs and StreamableHTTPClientTransport. Per the advisory, any custom OAuthClientProvider should persist the new issuer field. No such provider exists in this repo today.

Validation:

  • yarn why @modelcontextprotocol/sdk shows only 1.32.1.
  • yarn workspace @sourcebot/web test: 148 files and 1511 tests pass.
  • yarn workspace @sourcebot/web lint passes.
  • Web tsc --noEmit: no MCP-related errors. The remaining errors are pre-existing asset-import and utils.ts errors unrelated to this change.

🤖 Generated with Claude Code


Note

Low Risk
Lockfile-only security patch with existing semver ranges; no custom OAuth client provider in the repo, so behavioral impact should be limited to the upstream SDK fix.

Overview
Security dependency bump for @modelcontextprotocol/sdk to 1.32.1 (CVE-2026-104850), addressing an OAuth client issue where credentials could be sent to an authorization server chosen by the MCP server.

There are no package.json or application code changes—only a Yarn lockfile refresh that deduplicates prior resolved versions (1.27.1 / 1.29.0) so all consumers resolve to 1.32.1, plus an Unreleased changelog entry under Fixed.

Reviewed by Cursor Bugbot for commit 048b3bd. Bugbot is set up for automated code reviews on this repo. Configure here.

…26-104850

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: f057de84-8378-4624-9c63-f2a835b971d9

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@claude
claude Bot requested a review from brendan-kellam October 9, 2026 14:51
@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

License Audit

⚠️ Status: PASS

Metric Count
Total packages 2181
Resolved (non-standard) 8
Unresolved 0
Strong copyleft 0
Weak copyleft 27

Weak Copyleft Packages (informational)

Package Version License
@img/sharp-libvips-darwin-arm64 1.3.4 LGPL-3.0-or-later
@img/sharp-libvips-darwin-x64 1.3.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm 1.3.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm64 1.3.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc64 1.3.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv64 1.3.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x 1.3.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-x64 1.3.4 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm64 1.3.4 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x64 1.3.4 LGPL-3.0-or-later
@img/sharp-wasm32 0.35.5 Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm64 0.35.5 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia32 0.35.5 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x64 0.35.5 Apache-2.0 AND LGPL-3.0-or-later
axe-core 4.10.3 MPL-2.0
lightningcss 1.32.0 MPL-2.0
lightningcss-android-arm64 1.32.0 MPL-2.0
lightningcss-darwin-arm64 1.32.0 MPL-2.0
lightningcss-darwin-x64 1.32.0 MPL-2.0
lightningcss-freebsd-x64 1.32.0 MPL-2.0
lightningcss-linux-arm-gnueabihf 1.32.0 MPL-2.0
lightningcss-linux-arm64-gnu 1.32.0 MPL-2.0
lightningcss-linux-arm64-musl 1.32.0 MPL-2.0
lightningcss-linux-x64-gnu 1.32.0 MPL-2.0
lightningcss-linux-x64-musl 1.32.0 MPL-2.0
lightningcss-win32-arm64-msvc 1.32.0 MPL-2.0
lightningcss-win32-x64-msvc 1.32.0 MPL-2.0
Resolved Packages (8)
Package Version Original Resolved Source
codemirror-lang-elixir 4.0.0 UNKNOWN Apache-2.0 installed package LICENSE file (node_modules), version matched
khroma 2.1.0 UNKNOWN MIT installed package LICENSE file (node_modules), version matched
lezer-elixir 1.1.2 UNKNOWN Apache-2.0 installed package LICENSE file (node_modules), version matched
map-stream 0.1.0 UNKNOWN MIT installed package LICENSE file (node_modules), version matched (LICENCE; MIT text)
memorystream 0.3.1 UNKNOWN MIT extracted from package.json licenses[].type object; confirmed by LICENSE file
pause-stream 0.0.11 MIT,Apache2 (MIT OR Apache-2.0) array value normalized ('Apache2' -> Apache-2.0); LICENSE file states 'Dual Licensed MIT and Apache 2'
posthog-js 1.369.0 SEE LICENSE IN LICENSE Apache-2.0 GitHub repo / installed LICENSE file (Apache License 2.0)
valid-url 1.0.9 UNKNOWN MIT installed package LICENSE file (node_modules), version matched

@brendan-kellam
brendan-kellam merged commit 92a3213 into main Oct 9, 2026
21 checks passed
@brendan-kellam
brendan-kellam deleted the cursor/cve/modelcontextprotocol-sdk branch October 9, 2026 14:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant