@ai-sdk/policy-opa is vulnerable to Missing Authorization
42
Medium Risk
@ai-sdk/policy-opa's wrapMcpTools resolves per tool approval entries with a plain property lookup, so a tool name matching an inherited Object.prototype member bypasses its approval map instead of falling back to the configured default. Separately, when a per tool entry is a function that returns not-applicable or undefined, wrapMcpTools passes that "no opinion" result straight through, letting the tool run without an approval request instead of routing it through the configured fallback. The fix builds the approval map with a null prototype and own-property checks, and forces function results with no opinion through the configured fallback.
You are affected if you are using a version that falls within the vulnerable range and you call wrapMcpTools with per tool approval configuration, including function-based per tool approvals.
@ai-sdk/policy-opa is vulnerable to Missing Authorization in versions 1.0.0 - 1.0.18.
Upgrade the @ai-sdk/policy-opa library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.