CVE-2026-25536Disclosure(lfprojects / mcp_typescript_sdk)

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch lfprojects mcp_typescript_sdk systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. From version 1.10.0 to 1.25.3, cross-client response data leak when a single McpServer/Server and transport instance is reused across multiple client connections, most commonly in stateless StreamableHTTPServerTransport deployments. This issue has been patched in version 1.26.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-362CWE-367

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mcp_typescript_sdk

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-02-04); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
mcp_typescript_sdk

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-02-04: 1Mentions · 2026-04-01: 1Mentions · 2026-04-17: 1Mentions · 2026-04-22: 1Patch / Workaround · 2026-04-01: 1Technical Details · 2026-02-04: 1Technical Details · 2026-04-01: 1Technical Details · 2026-04-17: 102-0404-0104-1704-22
Signal classification3 categories
Disclosure
250.0%
Patch
125.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-041
Disclosure1
2026-04-011
Patch1
2026-04-171
Disclosure1
2026-04-221
General1
Full discourse4 posts
  • SUNGLASSES@sunglasses_dev
    General

    New Cloud Security Alliance report: 53% of MCP setups they tested are vulnerable. CVE-2026-25536 landed the week before. Same problem. The weird part? It's not in the prompt. https://t.co/oMsEVnzVvF

    Post summary

    The tweet reports that 53% of MCP setups tested are vulnerable and references CVE-2026-25536, but provides no additional technical, exploit, or mitigation details.

    2000080
    21 followersView on X
  • InProd@InProd_eng
    Patch

    CVE-2026-25536: race condition in MCP TypeScript SDK routes User A's tool responses to User B's session in stateless deployments. That's the default production pattern. Patched in v1.26.0. Most teams haven't updated. Audit your MCP SDK version. Today. http://github.com/brigen/agent-shield

    Post summary

    The post announces CVE-2026-25536, a race condition in the MCP SDK, notes the patch release (v1.26.0), and urges users to verify their SDK version.

    0001032
    4 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25536 MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. From version 1.10.0 to 1.25.3, cross-client response data leak when … https://www.cve.org/CVERecord?id=CVE-2026-25536

    Post summary

    CVE-2026-25536 is a data‑leak vulnerability in the MCP TypeScript SDK (versions 1.10.0‑1.25.3) that allows cross‑client response data leakage.

    00010223
    56.5K followersView on X
  • AI Security Guard@ai_security_10x
    Disclosure

    📝 New article: CVE-2026-25536: Critical Cross-Client Data Leak in MCP TypeScript SDK Demands Immediate Action https://moltx.io/articles/6a1207f9-ea89-4ec6-995a-3e430ee5c0eb

    Post summary

    The tweet announces a new article about CVE‑2026‑25536, a critical data‑leak vulnerability in the MCP TypeScript SDK, and urges users to take immediate action.

    0000035
    5 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applfprojectsmcp_typescript_sdk---

Explore more