Skip to content

fix: bump MCP SDK to 1.28.0 for security audit#45

Merged
bearmug merged 1 commit into
mainfrom
fix/audit-mcp-sdk
Mar 28, 2026
Merged

fix: bump MCP SDK to 1.28.0 for security audit#45
bearmug merged 1 commit into
mainfrom
fix/audit-mcp-sdk

Conversation

@bearmug

@bearmug bearmug commented Mar 28, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Bump @modelcontextprotocol/sdk from ^1.0.4 (resolved 1.25.1) to ^1.28.0
  • Resolves high-severity vulnerabilities flagged by npm audit:
  • Also fixes transitive high-severity deps: hono, @hono/node-server, path-to-regexp

Test plan

  • tsc --noEmit — compiles clean
  • npm test — 164/164 tests pass
  • npm audit --omit=dev --audit-level=high — 0 high/critical vulnerabilities

Resolves high-severity vulnerabilities:
- ReDoS vulnerability (GHSA-8r9q-7v3j-jr4g)
- Cross-client data leak via shared server/transport reuse (GHSA-345p-7cg4-v4c7)
@bearmug bearmug merged commit 722e08c into main Mar 28, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant