OsVault/npm/@modelcontextprotocol/sdk
npm

@modelcontextprotocol/sdk

3 known vulnerabilities · 0 critical · 0 high

CVE-2026-0621

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

Published Jan 5, 2026
CVE-2026-25536

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

Published Feb 4, 2026
CVE-2025-66414

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

Published Dec 2, 2025
Check your entire dependency tree at onceRun dependency scan →