StackRadar

CVE-2026-104850

High

Advisory

Published 6 Oct 2026In the index since 7 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
42
of 18,035 indexed, latest versions
Container images
39
deployed by those charts
Fix available
2 of 2
affected packages

MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server

Carried by container images the latest versions of 42 of 18,035 indexed charts deploy, on 39 images.

Affected packageAffected versionsFixed inImages
@modelcontextprotocol/sdknpm1.12.0, 1.12.1, 1.13.3, 1.20.2+5 more1.31.038
@modelcontextprotocol/clientnpm2.1.02.2.01
OSV records
GHSA-6qxp-vccf-f47h

Charts affected

42 by stars
ChartLatestAffected imagesRadar Score
n8ncommunity-chartsVerified publisher1.24.431 of 1See more

n8n community-charts 1.24.43

1 of the 1 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
n8nio/n8n:2.41.687e0bab2c931
@modelcontextprotocol/sdk@1.26.0
1.31.0

Open the chart page →

1,436
n8nopen-8gears2.1.11 of 1See more

n8n open-8gears 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.8cfe2704ff858
@modelcontextprotocol/sdk@1.26.0
1.31.0

Open the chart page →

2,298
backstagebackstageOfficialVerified publisher2.10.21 of 1See more

backstage backstage 2.10.2

1 of the 1 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
ghcr.io/backstage/backstage:lateste2a48bb6ab55
@modelcontextprotocol/sdk@1.30.0
1.31.0

Open the chart page →

1,342
penpotpenpotOfficialVerified publisher1.11.31 of 5See more

penpot penpot 1.11.3

1 of the 5 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
penpotapp/mcp:2.18.35e811e6eeb17
@modelcontextprotocol/sdk@1.30.0
1.31.0

Open the chart page →

6,130
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.391e4f0a7feed
@modelcontextprotocol/sdk@1.20.2
1.31.0

Open the chart page →

13,565
openclawopenclaw-helmVerified publisher1.5.401 of 2See more

openclaw openclaw-helm 1.5.40

1 of the 2 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
@modelcontextprotocol/sdk@1.29.0
1.31.0

Open the chart page →

6,594
openclawopenclawVerified publisher1.105.11 of 2See more

openclaw openclaw 1.105.1

1 of the 2 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-openclaw/openclaw:1.105.13f87eebbba88
@modelcontextprotocol/sdk@1.30.0
1.31.0

Open the chart page →

2,763
n8nhelmforgeVerified publisher2.1.31 of 2See more

n8n helmforge 2.1.3

1 of the 2 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
n8nio/n8n:2.41.3fdce8f852ac7
@modelcontextprotocol/sdk@1.26.0
1.31.0

Open the chart page →

1,797
docmosthelmforgeVerified publisher1.4.11 of 4See more

docmost helmforge 1.4.1

1 of the 4 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
docmost/docmost:0.96.0b56947fcfd08
@modelcontextprotocol/sdk@1.30.0
1.31.0

Open the chart page →

4,393
nocodbzekker6Verified publisher1.10.01 of 1See more

nocodb zekker6 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
nocodb/nocodb:0.301.5d9516f0bf546
@modelcontextprotocol/sdk@1.27.1
1.31.0

Open the chart page →

5,239
agentareaagentareaVerified publisher0.0.261 of 17See more

agentarea agentarea 0.0.26

1 of the 17 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
agentarea/agentarea-mcp-base:latestcd57c37971a0
@modelcontextprotocol/client@2.1.0
2.2.0

Open the chart page →

16,620
betterdb-monitorbetterdb-monitorOfficialVerified publisher0.49.01 of 1See more

betterdb-monitor betterdb-monitor 0.49.0

1 of the 1 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
betterdb/monitor:0.49.0-no-ai97dcd2d2192f
@modelcontextprotocol/sdk@1.27.1
1.31.0

Open the chart page →

421
directusdirectus-io2.1.01 of 3See more

directus directus-io 2.1.0

1 of the 3 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
directus/directus:12.0.29c8470ea465c
@modelcontextprotocol/sdk@1.29.0
1.31.0

Open the chart page →

9,382
n8nn8n-helm2.25.71 of 1See more

n8n n8n-helm 2.25.7

1 of the 1 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
n8nio/n8n:2.25.7761374d4eb84
@modelcontextprotocol/sdk@1.26.0
1.31.0

Open the chart page →

3,858
observability-mcpobservability-mcpOfficialVerified publisher2.9.131 of 2See more

observability-mcp observability-mcp 2.9.13

1 of the 2 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
ghcr.io/thotischner/observability-mcp:3.9.12d4eeee759ea7
@modelcontextprotocol/sdk@1.30.1
1.31.0

Open the chart page →

36
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
treskon/portrait-ui:DEV-lateste7970783bc8d
@modelcontextprotocol/sdk@1.30.0
1.31.0

Open the chart page →

36,191
supabasesupabse0.8.01 of 11See more

supabase supabse 0.8.0

1 of the 11 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
@modelcontextprotocol/sdk@1.29.0
1.31.0

Open the chart page →

21,571
adeptia-automate-mcpadeptia-automate-mcp1.0.02 of 2See more

adeptia-automate-mcp adeptia-automate-mcp 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
@modelcontextprotocol/sdk@1.26.0
1.31.0
adeptiainc/adeptia-automate-observe:1.0.031f295e948e6
@modelcontextprotocol/sdk@1.27.1
1.31.0

Open the chart page →

4,293
activepiecesadnoctemVerified publisher0.7.01 of 1See more

activepieces adnoctem 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
activepieces/activepieces:0.92.1d22e3f36f78d
@modelcontextprotocol/sdk@1.27.1
1.31.0

Open the chart page →

1,814
outlineadnoctemVerified publisher0.1.21 of 1See more

outline adnoctem 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
outlinewiki/outline:1.10.1832051f039b4
@modelcontextprotocol/sdk@1.29.0
1.31.0

Open the chart page →

2,001
mcp-for-argocdchristianhuthVerified publisher2.0.01 of 1See more

mcp-for-argocd christianhuth 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
ghcr.io/argoproj-labs/mcp-for-argocd:v0.9.0dffc6c719d86
@modelcontextprotocol/sdk@1.29.0
1.31.0

Open the chart page →

2,273
dapr-agentsdapr-agents-devVerified publisher0.1.51 of 31See more

dapr-agents dapr-agents-dev 0.1.5

1 of the 31 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
ghcr.io/kagent-dev/doc2vec/mcp:1.1.14ace1de323f4a
@modelcontextprotocol/sdk@1.12.1
1.31.0

Open the chart page →

28,302
decisionrules-aksdecisionrules-aksVerified publisher0.3.01 of 2See more

decisionrules-aks decisionrules-aks 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
decisionrules/server:latestbb3a93224b5a
@modelcontextprotocol/sdk@1.30.0
1.31.0

Open the chart page →

493
decisionrules-eksdecisionrules-eksVerified publisher0.4.01 of 2See more

decisionrules-eks decisionrules-eks 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
decisionrules/server:latestbb3a93224b5a
@modelcontextprotocol/sdk@1.30.0
1.31.0

Open the chart page →

493
decisionrules-ingressdecisionrules-ingressVerified publisher0.3.01 of 2See more

decisionrules-ingress decisionrules-ingress 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
decisionrules/server:latestbb3a93224b5a
@modelcontextprotocol/sdk@1.30.0
1.31.0

Open the chart page →

493
decisionrules-ocpdecisionrules-ocpVerified publisher0.2.01 of 4See more

decisionrules-ocp decisionrules-ocp 0.2.0

1 of the 4 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
decisionrules/server:latestbb3a93224b5a
@modelcontextprotocol/sdk@1.30.0
1.31.0

Open the chart page →

1,554
dial-admindialVerified publisher0.19.01 of 3See more

dial-admin dial 0.19.0

1 of the 3 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
epam/ai-dial-admin-frontend:0.21.01ecee9f1aa09
@modelcontextprotocol/sdk@1.30.0
1.31.0

Open the chart page →

4,215
bytestashhelmforgeVerified publisher1.0.11 of 1See more

bytestash helmforge 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
ghcr.io/jordan-dalby/bytestash:1.5.130decae44290a
@modelcontextprotocol/sdk@1.30.1
1.31.0

Open the chart page →

23
reactive-resumehelmforgeVerified publisher1.0.01 of 4See more

reactive-resume helmforge 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
ghcr.io/amruthpillai/reactive-resume:v5.3.0c487ec5edcfe
@modelcontextprotocol/sdk@1.30.0
1.31.0

Open the chart page →

3,588
strapihelmforgeVerified publisher2.3.151 of 3See more

strapi helmforge 2.3.15

1 of the 3 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
helmforge/strapi-base:5.52.270e9143d6d92
@modelcontextprotocol/sdk@1.30.0
1.31.0

Open the chart page →

2,725
nocodbinseefrlab0.2.01 of 1See more

nocodb inseefrlab 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
nocodb/nocodb:latest4ccfc5114506
@modelcontextprotocol/sdk@1.30.0
1.31.0

Open the chart page →

905
mcp-gitlabmcp-helmVerified publisher0.3.41 of 1See more

mcp-gitlab mcp-helm 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
iwakitakuma/gitlab-mcp:2.0.7fb3e81aa6528
@modelcontextprotocol/sdk@1.13.3
1.31.0

Open the chart page →

1,317
mcp-kubernetesmcp-helmVerified publisher0.2.71 of 1See more

mcp-kubernetes mcp-helm 0.2.7

1 of the 1 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
mcp/kubernetes:latest5ffbf7f0a8aa
@modelcontextprotocol/sdk@1.26.0
1.31.0

Open the chart page →

6,473
n8nn8n-openshiftVerified publisher1.18.01 of 1See more

n8n n8n-openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
@modelcontextprotocol/sdk@1.26.0
1.31.0

Open the chart page →

2,298
cloakbrowser-mcpobeoneVerified publisher0.3.31 of 1See more

cloakbrowser-mcp obeone 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
swimmwatch/cloakbrowser-mcp:1.14.1f6986203a121
@modelcontextprotocol/sdk@1.30.0
1.31.0

Open the chart page →

2,642
n8nopenshift1.18.01 of 1See more

n8n openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
@modelcontextprotocol/sdk@1.26.0
1.31.0

Open the chart page →

2,298
portalplatform-mesh-portal0.21.31 of 1See more

portal platform-mesh-portal 0.21.3

1 of the 1 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
ghcr.io/platform-mesh/portal:v0.27.3966b1a9378b6
@modelcontextprotocol/sdk@1.26.0
1.31.0

Open the chart page →

396
rybbitrybbit-helm1.3.21 of 7See more

rybbit rybbit-helm 1.3.2

1 of the 7 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
@modelcontextprotocol/sdk@1.29.0
1.31.0

Open the chart page →

8,342
supabaseteochenglim0.1.21 of 13See more

supabase teochenglim 0.1.2

1 of the 13 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
supabase/studio:latestfdb56cfa1705
@modelcontextprotocol/sdk@1.29.0
1.31.0

Open the chart page →

10,711
unleash-enterpriseunleash1.0.31 of 1See more

unleash-enterprise unleash 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
unleashorg/unleash-enterprise:7.5.0245aeba40053
@modelcontextprotocol/sdk@1.26.0
1.31.0

Open the chart page →

2,493
n8nvictorlane1.0.181 of 1See more

n8n victorlane 1.0.18

1 of the 1 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
n8nio/n8n:1.115.1ed16e560c40e
@modelcontextprotocol/sdk@1.12.0
1.31.0

Open the chart page →

7,534
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-104850.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
@modelcontextprotocol/sdk@1.20.2
1.31.0

Open the chart page →

7,247

Container images carrying it

39 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
decisionrules/server:latestbb3a93224b5a
@modelcontextprotocol/sdk@1.30.0
1.31.0
4
n8nio/n8n:2.36.714c4285bc303
@modelcontextprotocol/sdk@1.26.0
1.31.0
2
activepieces/activepieces:0.92.1d22e3f36f78d
@modelcontextprotocol/sdk@1.27.1
1.31.0
1
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
@modelcontextprotocol/sdk@1.26.0
1.31.0
1
adeptiainc/adeptia-automate-observe:1.0.031f295e948e6
@modelcontextprotocol/sdk@1.27.1
1.31.0
1
agentarea/agentarea-mcp-base:latestcd57c37971a0
@modelcontextprotocol/client@2.1.0
2.2.0
1
betterdb/monitor:0.49.0-no-ai97dcd2d2192f
@modelcontextprotocol/sdk@1.27.1
1.31.0
1
directus/directus:12.0.29c8470ea465c
@modelcontextprotocol/sdk@1.29.0
1.31.0
1
docmost/docmost:0.96.0b56947fcfd08
@modelcontextprotocol/sdk@1.30.0
1.31.0
1
epam/ai-dial-admin-frontend:0.21.01ecee9f1aa09
@modelcontextprotocol/sdk@1.30.0
1.31.0
1
helmforge/strapi-base:5.52.270e9143d6d92
@modelcontextprotocol/sdk@1.30.0
1.31.0
1
iwakitakuma/gitlab-mcp:2.0.7fb3e81aa6528
@modelcontextprotocol/sdk@1.13.3
1.31.0
1
mcp/kubernetes:latest5ffbf7f0a8aa
@modelcontextprotocol/sdk@1.26.0
1.31.0
1
n8nio/n8n:2.25.7761374d4eb84
@modelcontextprotocol/sdk@1.26.0
1.31.0
1
n8nio/n8n:2.41.687e0bab2c931
@modelcontextprotocol/sdk@1.26.0
1.31.0
1
n8nio/n8n:2.36.8cfe2704ff858
@modelcontextprotocol/sdk@1.26.0
1.31.0
1
n8nio/n8n:1.115.1ed16e560c40e
@modelcontextprotocol/sdk@1.12.0
1.31.0
1
n8nio/n8n:2.41.3fdce8f852ac7
@modelcontextprotocol/sdk@1.26.0
1.31.0
1
nocodb/nocodb:latest4ccfc5114506
@modelcontextprotocol/sdk@1.30.0
1.31.0
1
nocodb/nocodb:0.301.5d9516f0bf546
@modelcontextprotocol/sdk@1.27.1
1.31.0
1
outlinewiki/outline:1.10.1832051f039b4
@modelcontextprotocol/sdk@1.29.0
1.31.0
1
penpotapp/mcp:2.18.35e811e6eeb17
@modelcontextprotocol/sdk@1.30.0
1.31.0
1
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
@modelcontextprotocol/sdk@1.29.0
1.31.0
1
supabase/studio:latestfdb56cfa1705
@modelcontextprotocol/sdk@1.29.0
1.31.0
1
swimmwatch/cloakbrowser-mcp:1.14.1f6986203a121
@modelcontextprotocol/sdk@1.30.0
1.31.0
1
treskon/portrait-ui:DEV-lateste7970783bc8d
@modelcontextprotocol/sdk@1.30.0
1.31.0
1
unleashorg/unleash-enterprise:7.5.0245aeba40053
@modelcontextprotocol/sdk@1.26.0
1.31.0
1
wazuh/wazuh-dashboard:4.14.491c8d793746f
@modelcontextprotocol/sdk@1.20.2
1.31.0
1
wazuh/wazuh-dashboard:4.14.391e4f0a7feed
@modelcontextprotocol/sdk@1.20.2
1.31.0
1
ghcr.io/amruthpillai/reactive-resume:v5.3.0c487ec5edcfe
@modelcontextprotocol/sdk@1.30.0
1.31.0
1
ghcr.io/argoproj-labs/mcp-for-argocd:v0.9.0dffc6c719d86
@modelcontextprotocol/sdk@1.29.0
1.31.0
1
ghcr.io/backstage/backstage:lateste2a48bb6ab55
@modelcontextprotocol/sdk@1.30.0
1.31.0
1
ghcr.io/jordan-dalby/bytestash:1.5.130decae44290a
@modelcontextprotocol/sdk@1.30.1
1.31.0
1
ghcr.io/kagent-dev/doc2vec/mcp:1.1.14ace1de323f4a
@modelcontextprotocol/sdk@1.12.1
1.31.0
1
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
@modelcontextprotocol/sdk@1.29.0
1.31.0
1
ghcr.io/platform-mesh/portal:v0.27.3966b1a9378b6
@modelcontextprotocol/sdk@1.26.0
1.31.0
1
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
@modelcontextprotocol/sdk@1.29.0
1.31.0
1
ghcr.io/thotischner/observability-mcp:3.9.12d4eeee759ea7
@modelcontextprotocol/sdk@1.30.1
1.31.0
1
registry.gitlab.com/xrow-public/helm-openclaw/openclaw:1.105.13f87eebbba88
@modelcontextprotocol/sdk@1.30.0
1.31.0
1

syft 1.42.1 · advisories as of 7 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.