CVE-2026-108586
1MCP Agent 0.20.0 through 0.39.0 OAuth Tag-Scope Bypass via Negated Tag Filter
CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th
1MCP Agent (@1mcp/agent) 0.20.0 through 0.39.0 contains an incorrect authorization vulnerability that allows authenticated clients to bypass OAuth tag-scope enforcement using negated advanced tag-filter expressions. Attackers holding a single-tag token can send a filter like not <granted-tag> to list and invoke tools on backend MCP servers outside their granted scopes.
| CWE | CWE-863 |
| Vendor | 1mcp-app |
| Product | @1mcp/agent |
| Published | Oct 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for 1mcp-app @1mcp/agent
Be the first to know when new medium vulnerabilities affecting 1mcp-app @1mcp/agent are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
Affected Versions
1mcp-app / @1mcp/agent
0.20.0 โค 0.39.0
References
hackmd.io: https://hackmd.io/@haind/1mcp-negated-tag-filter-oauth-scope-bypass github.com: https://github.com/1mcp-app/agent/blob/v0.39.0/src/sdk/legacy/transport/http/middlewares/scopeAuthMiddleware.ts#L163-L183 github.com: https://github.com/1mcp-app/agent/blob/v0.39.0/src/transport/http/routes/inspectHelpers.ts#L79-L102 github.com: https://github.com/1mcp-app/agent vulncheck.com: https://www.vulncheck.com/advisories/1mcp-agent-0.20.0-through-0.39.0-oauth-tag-scope-bypass-via-negated-tag-filter
Credits
HaiND from the Post and Telecommunication Institute of Technology