Model Context Protocol implementation for TypeScript
93%
Total Score
67
100
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-25536 @modelcontextprotocol/sdk is vulnerable to Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in versions 1.10.0 - 1.25.3. | 1.10.0 - 1.25.3 | High |
CVE-2026-0621 @modelcontextprotocol/sdk is vulnerable to Inefficient Regular Expression Complexity in versions 0.0.0 - 1.25.2. | 0.0.0 - 1.25.2 | High |
CVE-2025-66414 @modelcontextprotocol/sdk is vulnerable to Reliance on Reverse DNS Resolution for a Security-Critical Action in versions 0.0.0 - 1.24.0. | 0.0.0 - 1.24.0 | High |
AIKIDO-2025-10583 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @modelcontextprotocol/sdk is vulnerable to Cross-site Scripting (XSS) in versions 0.0.1 - 1.17.3. | 0.0.1 - 1.17.3 | Medium |
AIKIDO-2025-10459 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @modelcontextprotocol/sdk is vulnerable to Insufficient Session Expiration in versions 1.6.0 - 1.15.0. | 1.6.0 - 1.15.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
ajv Version ^8.17.1 | — | — |
zod Version ^3.25 || ^4.0 | — | — |
cors Version ^2.8.5 | — | — |
hono Version ^4.11.4 | — | — |
jose Version ^6.1.3 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant