io.modelcontextprotocol.sdk:mcp-core

Licenses: MIT

Direct Vulnerabilities

Known vulnerabilities in the io.modelcontextprotocol.sdk:mcp-core package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Origin Validation Error

[,0.18.0)
  • M
Permissive Cross-domain Policy with Untrusted Domains

[,1.0.1)[1.1.0,1.1.1)

Package versions

16 VERSIONS IN TOTAL See all versions
versionpublisheddirect vulnerabilities
1.1.127 Mar, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
1.1.013 Mar, 2026
  • 0
    C
  • 0
    H
  • 1
    M
  • 0
    L
1.0.127 Mar, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
1.0.023 Feb, 2026
  • 0
    C
  • 0
    H
  • 1
    M
  • 0
    L
1.0.0-RC320 Feb, 2026
  • 0
    C
  • 0
    H
  • 1
    M
  • 0
    L
0.18.119 Feb, 2026
  • 0
    C
  • 0
    H
  • 1
    M
  • 0
    L
0.18.018 Feb, 2026
  • 0
    C
  • 0
    H
  • 1
    M
  • 0
    L
0.17.222 Jan, 2026
  • 0
    C
  • 1
    H
  • 1
    M
  • 0
    L
0.17.18 Jan, 2026
  • 0
    C
  • 1
    H
  • 1
    M
  • 0
    L
0.17.04 Dec, 2025
  • 0
    C
  • 1
    H
  • 1
    M
  • 0
    L