GHSA-w48q-cv73-mx4w: Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
- Identifiers
- CVE-2025-66414GHSA-w48q-cv73-mx4w
- Published
- Record updated
- Affected
- @modelcontextprotocol/sdk < 1.24.0
- Fixed in
- 1.24.0
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.5%
Summary
The Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default for HTTP-based servers. When such a server runs on localhost without authentication, using StreamableHTTPServerTransport or SSEServerTransport without enableDnsRebindingProtection enabled, a malicious website could bypass same-origin policy restrictions and invoke tools or access resources on the user's behalf. The issue does not affect servers using stdio transport.
Mitigation
Servers created via createMcpExpressApp() now have this protection enabled by default when binding to localhost. Users with custom Express configurations are advised to update to version 1.24.0 and apply the exported hostHeaderValidation() middleware when running an unauthenticated server on localhost.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- @modelcontextprotocol/sdknpmLLM dependency since 2024-11-11 · 18 tracked dependents
Topics
Related items
- HighCVE-2026-101998: Docker Sandboxes fail open when masking credentials in proxy responsesSame vendor · NVD/CVE Database
- HighCVE-2026-103435: Claude Code symlink race condition allows writes outside project directorySame vendor · NVD/CVE Database
- HighGHSA-6qxp-vccf-f47h: MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP serverSame vendor · GitHub Advisory Database
- HighCVE-2026-103012: Claude Code stored API key overrides organization policy sign-inSame vendor · NVD/CVE Database
- HighCVE-2026-100585: OpenClaw permission prompt approval bypass through MCP channel bridgeSame vendor · NVD/CVE Database