Generated remediation guidance and an executive summary. No account required.
MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. From version 1.10.0 to 1.25.3, cross-client response data leak when a single McpServer/Server and transport instance is reused across multiple client connections, most commonly in stateless StreamableHTTPServerTransport deployments. This issue has been patched in version 1.26.0.
Cite this page
CVE-2026-25536. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2026-25536
Use CWE-362, Lfprojects vendor hub and Mcp Typescript Sdk product page to widen CVE-2026-25536 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-0621 and CVE-2025-66414 for nearby disclosures in the same product family.