dotsagent.io
Language:English
CVE-2026-25536

MCP TypeScript SDK leaked responses between clients

MCP servers on the TypeScript SDK that shared one server or transport instance across clients could send one client's responses to another. Fixed in 1.26.0.

What happened

Advisory GHSA-345p-7cg4-v4c7, published on 4 February 2026 as CVE-2026-25536, covers MCP servers built with the TypeScript SDK. When a server reused one server or transport instance for several clients, responses meant for one client could reach another.

Version 1.26.0 of the SDK fixes the issue.

Why it worked

A shared server or transport object holds state for every connected client at once. When responses are matched to requests through that shared state, one client's answer can be delivered to someone else.

What to do

  • Update the MCP TypeScript SDK to 1.26.0 or later.
  • Create a new server and transport instance for each session.
  • Bind each session to the authenticated user and check it on every request.
  • Test with two clients in parallel to confirm their data stays separate.

Isolate MCP sessions and tenants

Work through the security checklist →

Sources

  1. github.com/advisories/GHSA-345p-7cg4-v4c7

Independent reference for people who build AI agents. Not affiliated with any vendor named here.

© 2026 DotsAgent · Facts checked October 1, 2026