High severityNVD Advisory· Published Feb 4, 2026· Updated Feb 5, 2026
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
CVE-2026-25536
Description
MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. From version 1.10.0 to 1.25.3, cross-client response data leak when a single McpServer/Server and transport instance is reused across multiple client connections, most commonly in stateless StreamableHTTPServerTransport deployments. This issue has been patched in version 1.26.0.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@modelcontextprotocol/sdknpm | >= 1.10.0, < 1.26.0 | 1.26.0 |
Affected products
1- Range: >= 1.10.0, < 1.26.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- github.com/advisories/GHSA-345p-7cg4-v4c7ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-25536ghsaADVISORY
- github.com/modelcontextprotocol/typescript-sdk/issues/204ghsax_refsource_MISCWEB
- github.com/modelcontextprotocol/typescript-sdk/issues/243ghsax_refsource_MISCWEB
- github.com/modelcontextprotocol/typescript-sdk/security/advisories/GHSA-345p-7cg4-v4c7ghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.