@modelcontextprotocol/sdk

Model Context Protocol implementation for TypeScript
Licenses: MIT

Direct Vulnerabilities

Known vulnerabilities in the @modelcontextprotocol/sdk package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Race Condition

>=1.10.0 <1.26.0
  • H
Regular Expression Denial of Service (ReDoS)

>=1.3.0 <1.25.2
  • H
Insecure Default Initialization of Resource

<1.24.0

Package versions

78 VERSIONS IN TOTAL See all versions
versionpublisheddirect vulnerabilities
1.29.030 Mar, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
1.28.025 Mar, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
1.27.124 Feb, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
1.27.016 Feb, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
1.26.04 Feb, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
1.25.320 Jan, 2026
  • 0
    C
  • 1
    H
  • 0
    M
  • 0
    L
1.25.27 Jan, 2026
  • 0
    C
  • 1
    H
  • 0
    M
  • 0
    L
1.25.116 Dec, 2025
  • 0
    C
  • 2
    H
  • 0
    M
  • 0
    L
1.25.015 Dec, 2025
  • 0
    C
  • 2
    H
  • 0
    M
  • 0
    L
1.24.34 Dec, 2025
  • 0
    C
  • 2
    H
  • 0
    M
  • 0
    L