CVE-2026-25536

Source
https://cve.org/CVERecord?id=CVE-2026-25536
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-25536.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-25536
Aliases
Downstream
Related
Published
2026-02-04T21:29:38.276Z
Modified
2026-02-11T11:58:44.852741Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N CVSS Calculator
Summary
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Details

MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. From version 1.10.0 to 1.25.3, cross-client response data leak when a single McpServer/Server and transport instance is reused across multiple client connections, most commonly in stateless StreamableHTTPServerTransport deployments. This issue has been patched in version 1.26.0.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-362"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25536.json"
}
References

Affected packages

Git / github.com/modelcontextprotocol/typescript-sdk

Affected ranges

Type
GIT
Repo
https://github.com/modelcontextprotocol/typescript-sdk
Events
Database specific
{
    "versions": [
        {
            "introduced": "1.10.0"
        },
        {
            "fixed": "1.26.0"
        }
    ]
}

Affected versions

0.*
0.15.1
1.*
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.15.0
1.15.1
1.16.0
1.17.0
1.17.1
1.17.2
1.17.3
1.17.4
1.17.5
1.18.0
1.18.1
1.18.2
1.19.0
1.20.0
1.20.1
1.20.2
1.21.0
1.21.1
1.22.0
1.23.0
1.23.0-beta.0
1.24.0
1.24.1
1.24.2
1.24.3
1.25.0
1.25.1
v1.*
v1.25.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-25536.json"