Skip to content

Comments

🔒 security: Update @modelcontextprotocol/sdk to v1.25.1#21

Open
kevint-cerebras wants to merge 1 commit intomainfrom
security/update-mcp-sdk-v1.25.1
Open

🔒 security: Update @modelcontextprotocol/sdk to v1.25.1#21
kevint-cerebras wants to merge 1 commit intomainfrom
security/update-mcp-sdk-v1.25.1

Conversation

@kevint-cerebras
Copy link
Collaborator

Security Update

This PR addresses critical security vulnerabilities by updating the dependency.

Changes:

  • Upgraded from →
  • Added DNS rebinding protection fixes
  • Enhanced secure MCP server initialization
  • Bumped package version to for security release

Security Improvements:

✅ DNS rebinding protection
✅ Secure initialization of MCP server
✅ Latest security patches and fixes

Compatibility:

  • All existing imports and functionality remain unchanged
  • Backward compatible - no breaking changes to API
  • Tested imports and server initialization

GitHub Security Alert:

GitHub detected 2 vulnerabilities on the default branch - this update addresses those security issues.

Priority: High - Security fix
Impact: Minimal - No code changes required

- Upgrade from v0.5.0 to v1.25.1 for critical security fixes
- Includes DNS rebinding protection and secure MCP server initialization
- Maintains backward compatibility with existing code
- Bump package version to 1.3.4 for security release
@semgrep-app
Copy link

semgrep-app bot commented Jan 5, 2026

Legal Risk

The following dependencies were released under a license that
has been flagged by your organization for consideration.

Recommendation

While merging is not directly blocked, it's best to pause and consider what it means to use this license before continuing. If you are unsure, reach out to your security team or Semgrep admin to address this issue.

ISC

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant