What happened
Verified via NVD REST API (published 2026-10-10, VulnCheck). The scope auth middleware evaluates the filter while the inspect helpers build the tool list without enforcing the token grant.
Why it matters
MCP agent brokers use OAuth tag scopes as the security boundary between a client and backend tools; a negation-based scope bypass breaks that boundary and gives low-privilege clients access to backend MCP servers they were not authorized to call.
Attack vector
Negated advanced tag-filter expressions (e.g. not <granted-tag>) are not correctly intersected with the OAuth tag scope, so a client with a single-tag token can pass a filter that matches everything outside its grant and list/invoke restricted tools (CWE-863).
Affected systems
@1mcp/agent 0.20.0 through 0.39.0 (scopeAuthMiddleware)
Mitigation
Upgrade past 0.39.0; validate tag-filter negotiation so negated expressions can never widen an OAuth-granted scope. See VulnCheck advisory.