VYPR

Typescript SDK

by Modelcontextprotocol

Source repositories

CVEs (3)

  • CVE-2026-25536Feb 4, 2026
    risk 0.00cvss epss 0.00

    MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. From version 1.10.0 to 1.25.3, cross-client response data leak when a single McpServer/Server and transport instance is reused across multiple client connections, most commonly in…

  • CVE-2026-0621Jan 5, 2026
    risk 0.00cvss epss 0.00

    Anthropic's MCP TypeScript SDK versions up to and including 1.25.1 contain a regular expression denial of service (ReDoS) vulnerability in the UriTemplate class when processing RFC 6570 exploded array patterns. The dynamically generated regular expression used during URI…

  • CVE-2025-66414Dec 2, 2025
    risk 0.00cvss epss 0.00

    MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Prior to 1.24.0, The Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default for HTTP-based servers. When an HTTP-based MCP server is run on…