PT-2026-6315 · Unknown · Mcp Typescript Sdk

Ahabian

+1

·

Published

2026-02-04

·

Updated

2026-04-22

·

CVE-2026-25536

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions MCP TypeScript SDK versions 1.10.0 through 1.25.3
Description The MCP TypeScript SDK, designed for Model Context Protocol servers and clients, exhibits a cross-client response data leak. This occurs when a single McpServer/Server and transport instance is reused across multiple client connections, particularly in stateless StreamableHTTPServerTransport deployments. The issue has been addressed in version 1.26.0.
Recommendations Update to version 1.26.0 or later.

Exploit

Fix

Race Condition

Weakness Enumeration

Related Identifiers

CVE-2026-25536
GHSA-345P-7CG4-V4C7
GHSA-W2FM-25VW-VH7F

Affected Products

Mcp Typescript Sdk