3.6.0
1 years ago
7 days ago
Known vulnerabilities in the mcp-mesh package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
mcp-mesh is a Kubernetes-native platform for distributed MCP applications Affected versions of this package are vulnerable to Race Condition within a Thread due to a Race Condition in Access Control. The agent shutdown process fails to atomically remove agents from the registry before termination, leading to a window where terminated agents remain in the active registry, allowing unauthorized requests to be routed to or authenticated as non-existent agents. How to fix Race Condition within a Thread? Upgrade | [,0.5.6) |