CVE-2026-108586: 1MCP Agent 0.20.0 through 0.39.0 OAuth Tag-Scope Bypass via Negated Tag Filter
1MCP Agent (@1mcp/agent) 0.20.0 through 0.39.0 contains an incorrect authorization vulnerability that allows authenticated clients to bypass OAuth tag-scope enforcement using negated advanced tag-filter expressions. Attackers holding a single-tag token can send a filter like not <granted-tag> to list and invoke tools on backend MCP servers outside their granted scopes.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs to be an authenticated client with an OAuth token that grants at least one tag. The issue is relevant where the agent uses OAuth tag scopes to restrict which backend MCP server tools a client may list or invoke.
What does an attacker need to send to bypass the scope restriction?
The attacker can use a negated advanced tag-filter expression, such as "not <granted-tag>". With a single-tag token, this can cause tools on backend MCP servers outside the token's granted tag scope to be listed and invoked.
Which versions are affected?
Affected versions are @1mcp/agent 0.20.0 through 0.39.0, inclusive.