
Two CVEs (CVE-2026-30889 and CVE-2026-31200) were classic JSON-RPC parser bugs in popular MCP client SDKs. One allowed a server response to set arbitrary properties on the client's session-state object via prototype pollution. The other allowed a server to inject batched…
Post summary
The post reports two JSON‑RPC parser bugs (CVE‑2026‑30889 and CVE‑2026‑31200) that enable servers to manipulate client session state via prototype pollution and batched injections, but provides no evidence of exploitation, patch, or PoC.


