VDB
KO

GO-2026-5273

MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry

Details

MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience in github.com/modelcontextprotocol/registry

Are you affected?

Enter the version of the package you're using.

Affected packages

Go / github.com/modelcontextprotocol/registry
Introduced in: 0 Fixed in: 1.7.6
Fix go get github.com/modelcontextprotocol/registry@v1.7.6

References