Skip to content

Commit 50547ed

Browse files
committed
fix: upgrade mcp-handler and SDK to patch cross-tenant response leak (CVE-2026-25536)
Upgrades mcp-handler from 1.0.2 to 1.1.0 and @modelcontextprotocol/sdk from 1.15.1 to 1.29.0 to fix a high-severity vulnerability where concurrent requests sharing the same StreamableHTTPServerTransport singleton could have their responses routed to the wrong client. Ref: GHSA-w2fm-25vw-vh7f, CVE-2026-25536 Made-with: Cursor
1 parent afc85c3 commit 50547ed

2 files changed

Lines changed: 86 additions & 8 deletions

File tree

0 commit comments

Comments
 (0)