Intel

AIKIDO-2026-141243

@ai-sdk/policy-opa is vulnerable to Missing Authorization

Missing Authorization Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published 2 days ago

42

Medium Risk

This Affects:

JS@ai-sdk/policy-opa
1.0.0 - 1.0.18
Fixed in 1.0.19
Are you affected? Scan for Free

TL;DR

@ai-sdk/policy-opa's wrapMcpTools resolves per tool approval entries with a plain property lookup, so a tool name matching an inherited Object.prototype member bypasses its approval map instead of falling back to the configured default. Separately, when a per tool entry is a function that returns not-applicable or undefined, wrapMcpTools passes that "no opinion" result straight through, letting the tool run without an approval request instead of routing it through the configured fallback. The fix builds the approval map with a null prototype and own-property checks, and forces function results with no opinion through the configured fallback.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you call wrapMcpTools with per tool approval configuration, including function-based per tool approvals.

Background info

@ai-sdk/policy-opa is vulnerable to Missing Authorization in versions 1.0.0 - 1.0.18.

How to fix this

Upgrade the @ai-sdk/policy-opa library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform