Skip to content
HighVulnerability

GHSA-w48q-cv73-mx4w: Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

Published
Record updated
View JSON
Affected
  • @modelcontextprotocol/sdk < 1.24.0
Fixed in
1.24.0
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.5%

Summary

The Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default for HTTP-based servers. When such a server runs on localhost without authentication, using StreamableHTTPServerTransport or SSEServerTransport without enableDnsRebindingProtection enabled, a malicious website could bypass same-origin policy restrictions and invoke tools or access resources on the user's behalf. The issue does not affect servers using stdio transport.

Mitigation

Servers created via createMcpExpressApp() now have this protection enabled by default when binding to localhost. Users with custom Express configurations are advised to update to version 1.24.0 and apply the exported hostHeaderValidation() middleware when running an unauthenticated server on localhost.