Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Gh-Arpeet

#39026of 53,635
7.1Total CVSS
Vulnerabilities · 1
PT-2026-6315
7.1
2026-02-04
Unknown · Mcp Typescript Sdk · CVE-2026-25536
**Name of the Vulnerable Software and Affected Versions** MCP TypeScript SDK versions 1.10.0 through 1.25.3 **Description** The MCP TypeScript SDK, designed for Model Context Protocol servers and clients, exhibits a cross-client response data leak. This occurs when a single `McpServer`/Server and transport instance is reused across multiple client connections, particularly in stateless `StreamableHTTPServerTransport` deployments. The issue has been addressed in version 1.26.0. **Recommendations** Update to version 1.26.0 or later.