CVE-2026-25536MCP TypeScript SDK leaked responses between clients
MCP servers on the TypeScript SDK that shared one server or transport instance across clients could send one client's responses to another. Fixed in 1.26.0.
What happened
Advisory GHSA-345p-7cg4-v4c7, published on 4 February 2026 as CVE-2026-25536, covers MCP servers built with the TypeScript SDK. When a server reused one server or transport instance for several clients, responses meant for one client could reach another.
Version 1.26.0 of the SDK fixes the issue.
Why it worked
A shared server or transport object holds state for every connected client at once. When responses are matched to requests through that shared state, one client's answer can be delivered to someone else.
What to do
- Update the MCP TypeScript SDK to 1.26.0 or later.
- Create a new server and transport instance for each session.
- Bind each session to the authenticated user and check it on every request.
- Test with two clients in parallel to confirm their data stays separate.
Isolate MCP sessions and tenants
Comment and Control: PR text steals secrets from CI agents
ClawHavoc: hundreds of malicious ClawHub skills spread AMOS
Work through the security checklist →