Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
Vulnerabilities
search
All ecosystems
605185
AlmaLinux
4582
Alpaquita
8714
Alpine
4040
Android
3262
BellSoft Hardened Containers
406
Bitnami
6828
Chainguard
5451
CleanStart
713
CRAN
14
crates.io
2191
Debian
53957
Echo
3132
GHC
3
GIT
81453
GitHub Actions
49
Go
6437
Hackage
30
Hex
57
Julia
409
Linux
15361
Mageia
5860
Maven
6273
MinimOS
19701
npm
216930
NuGet
1621
opam
11
openEuler
6219
openSUSE
12357
OSS-Fuzz
3817
Packagist
5993
Pub
11
PyPI
18482
Red Hat
19086
Rocky Linux
2883
Root
11671
RubyGems
1924
SUSE
20099
SwiftURL
50
Ubuntu
51656
VSCode
18
Wolfi
3434
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-345p-7cg4-v4c7
npm/@modelcontextprotocol/sdk
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
04 Feb
Fix available
Severity - 7.1 (High)
GHSA-8r9q-7v3j-jr4g
npm/@modelcontextprotocol/sdk
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
05 Jan
Fix available
Severity - 8.7 (High)
GHSA-w48q-cv73-mx4w
npm/@modelcontextprotocol/sdk
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
02 Dec 2025
Fix available
Severity - 7.6 (High)
GHSA-g9hg-qhmf-q45m
npm/@modelcontextprotocol/inspector
MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server
08 Sep 2025
Fix available
Severity - 8.6 (High)
GHSA-hc55-p739-j48w
npm/@modelcontextprotocol/server-filesystem
@modelcontextprotocol/server-filesystem vulnerability allows for path validation bypass via colliding path prefix
01 Jul 2025
Fix available
Severity - 7.3 (High)
GHSA-q66q-fx2p-7w4m
npm/@modelcontextprotocol/server-filesystem
@modelcontextprotocol/server-filesystem allows for path validation bypass via prefix matching and symlink handling
01 Jul 2025
Fix available
Severity - 7.3 (High)
GHSA-7f8r-222p-6f5g
npm/@modelcontextprotocol/inspector
MCP Inspector proxy server lacks authentication between the Inspector client and proxy
13 Jun 2025
Fix available
Severity - 9.4 (Critical)
npm - OSV