Skip to content
HighVulnerability

GHSA-345p-7cg4-v4c7: @modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

Published
Record updated
View JSON
Affected
  • @modelcontextprotocol/sdk >= 1.10.0, <= 1.25.3
Fixed in
1.26.0
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.4%

Summary

The advisory GHSA-345p-7cg4-v4c7 covers cross-client data leakage in @modelcontextprotocol/sdk, caused by reusing one StreamableHTTPServerTransport across multiple client requests, or one McpServer/Server instance across multiple transports. JSON-RPC message ID collisions, from clients whose default counter starts at 0, can route responses and notifications to the wrong client's HTTP stream. Stateless deployments without sessionIdGenerator are most exposed, and the two issues may affect a deployment separately or together.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.