CVE-2026-25536 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. From version 1.10.0 to 1.25.3, cross-client response data leak…
High CVSS: 7.1

CVE-2026-25536

MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. From version 1.10.0 to 1.25.3, cross-client response data leak when a single McpServer/Server and transport instance is reused across multiple client connections, most commonly in stateless StreamableHTTPServerTransport deployments. This issue has been patched in version 1.26.0.
Vendor
Lfprojects
Product
Mcp Typescript Sdk
CWE
CWE-362
Yayın Tarihi
2026-02-04 22:15:59
Güncelleme
2026-03-18 14:22:25
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar