PatchSiren

1mcp-app CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM 1mcp-app CVE published 2026-10-10

CVE-2026-108586

CVE-2026-108586 is a medium-severity vulnerability in 1MCP Agent versions 0.20.0 through 0.39.0 that allows authenticated clients to bypass OAuth tag-scope enforcement. This issue enables attackers with a single-tag token to list and invoke tools on backend MCP servers outside their granted scopes by using negated advanced tag-filter expressions. The vulnerability impacts 1MCP Agent deployments, particula [truncated]