Search Results (1 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-108586 1 1mcp-app 1 Agent 2026-10-11 5.4 Medium
1MCP Agent (@1mcp/agent) 0.20.0 through 0.39.0 contains an incorrect authorization vulnerability that allows authenticated clients to bypass OAuth tag-scope enforcement using negated advanced tag-filter expressions. Attackers holding a single-tag token can send a filter like not <granted-tag> to list and invoke tools on backend MCP servers outside their granted scopes.