HighVulnerability
GHSA-345p-7cg4-v4c7: @modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
- Identifiers
- CVE-2026-25536GHSA-345p-7cg4-v4c7
- Published
- Record updated
- Affected
- @modelcontextprotocol/sdk >= 1.10.0, <= 1.25.3
- Fixed in
- 1.26.0
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.4%
Summary
The advisory GHSA-345p-7cg4-v4c7 covers cross-client data leakage in @modelcontextprotocol/sdk, caused by reusing one StreamableHTTPServerTransport across multiple client requests, or one McpServer/Server instance across multiple transports. JSON-RPC message ID collisions, from clients whose default counter starts at 0, can route responses and notifications to the wrong client's HTTP stream. Stateless deployments without sessionIdGenerator are most exposed, and the two issues may affect a deployment separately or together.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Related items
- HighCVE-2026-101998: Docker Sandboxes fail open when masking credentials in proxy responsesSame vendor · NVD/CVE Database
- HighCVE-2026-103435: Claude Code symlink race condition allows writes outside project directorySame vendor · NVD/CVE Database
- HighGHSA-6qxp-vccf-f47h: MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP serverSame vendor · GitHub Advisory Database
- HighCVE-2026-103012: Claude Code stored API key overrides organization policy sign-inSame vendor · NVD/CVE Database
- HighCVE-2026-100585: OpenClaw permission prompt approval bypass through MCP channel bridgeSame vendor · NVD/CVE Database