{"id":"CVE-2026-108586","title":"1MCP Agent (@1mcp/agent) 0.20.0 through 0.39.0 contains an incorrect authorization vulnerability that allows authenticated clients to bypass OAuth tag-scope enforcement using negated advanced tag-filter expressions","summary":"1MCP Agent (@1mcp/agent) 0.20.0 through 0.39.0 contains an incorrect authorization vulnerability that allows authenticated clients to bypass OAuth tag-scope enforcement using negated advanced tag-filter expressions. Attackers holding a s…","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","cwe":["CWE-863"],"published":"2026-10-10","updated":"2026-10-10","sourceUpdated":"2026-10-10T17:17:00.593","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-108586","references":[{"url":"https://github.com/1mcp-app/agent","label":"disclosure@vulncheck.com"},{"url":"https://github.com/1mcp-app/agent/blob/v0.39.0/src/sdk/legacy/transport/http/middlewares/scopeAuthMiddleware.ts#L163-L183","label":"disclosure@vulncheck.com"},{"url":"https://github.com/1mcp-app/agent/blob/v0.39.0/src/transport/http/routes/inspectHelpers.ts#L79-L102","label":"disclosure@vulncheck.com"},{"url":"https://hackmd.io/@haind/1mcp-negated-tag-filter-oauth-scope-bypass","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/1mcp-agent-0.20.0-through-0.39.0-oauth-tag-scope-bypass-via-negated-tag-filter","label":"disclosure@vulncheck.com"}],"tags":["nvd"],"ingestedAt":"2026-10-10T17:28:24.990Z","slug":"CVE-2026-108586","body":"## Overview\n\n1MCP Agent (@1mcp/agent) 0.20.0 through 0.39.0 contains an incorrect authorization vulnerability that allows authenticated clients to bypass OAuth tag-scope enforcement using negated advanced tag-filter expressions. Attackers holding a single-tag token can send a filter like not <granted-tag> to list and invoke tools on backend MCP servers outside their granted scopes.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}