{"data":{"id":"4510ce0a-d396-4a89-87ef-fb7649f7e465","title":"GHSA-w48q-cv73-mx4w: Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default","summary":"The Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default for HTTP-based servers. When such a server runs on localhost without authentication, using StreamableHTTPServerTransport or SSEServerTransport without enableDnsRebindingProtection enabled, a malicious website could bypass same-origin policy restrictions and invoke tools or access resources on the user's behalf. The issue does not affect servers using stdio transport.","solution":"Servers created via createMcpExpressApp() now have this protection enabled by default when binding to localhost. Users with custom Express configurations are advised to update to version 1.24.0 and apply the exported hostHeaderValidation() middleware when running an unauthenticated server on localhost.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-w48q-cv73-mx4w","publishedAt":"2025-12-02T16:51:57.000Z","cveId":"CVE-2025-66414","cweIds":["CWE-350","CWE-1188"],"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":["other"],"issueType":"vulnerability","affectedPackages":["@modelcontextprotocol/sdk@< 1.24.0 (fixed: 1.24.0)"],"affectedPackageNames":["@modelcontextprotocol/sdk"],"affectedPackageRefs":["npm:@modelcontextprotocol/sdk"],"affectedVendors":["Anthropic"],"affectedVendorsRaw":["Model Context Protocol (MCP) TypeScript SDK"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00511,"epssCheckedAt":"2026-10-10T04:57:16.652Z","kevDateAdded":null,"advisoryAliases":["GHSA-w48q-cv73-mx4w"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2025-12-02T16:51:57.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}