CVE-2026-25536: Cross-Client Data Leak in the MCP TypeScript SDK
Practical DevSecOps·high signal
A vulnerability in the official MCP TypeScript SDK (versions 1.10.0–1.25.3, CVSS 7.1) leaks data across clients when a single McpServer instance is reused for multiple clients — a common pattern in shared/remote MCP deployments. Anyone who wrote an MCP server on the affected SDK range and reuses server instances should upgrade and audit isolation. This is a builder-facing bug, not a downstream-app bug.