Known vulnerabilities in MCP Python SDK
Vendor:
Model Context Protocol
Software:
MCP Python SDK
Software CPE:
cpe:2.3:a:modelcontextprotocol:python_sdk:*:*:*:*:*:*:*:*
Website:
https://modelcontextprotocol.io/
Total vulnerabilities:
4
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
2.0.0
1.29.0
1.28.1
1.28.0
1.27.2
1.27.1
1.27.0
1.26.0
1.25.0
1.24.0
1.23.3
1.23.2
1.23.1
1.23.0
1.22.0
1.21.2
1.21.1
1.21.0
1.20.0
1.19.0
1.18.0
1.17.0
1.16.0
1.15.0
1.14.1
1.14.0
1.13.1
1.13.0
1.12.4
1.12.3
1.12.2
1.12.1
1.12.0
1.11.0
1.10.1
1.10.0
1.9.4
1.9.3
1.9.2
1.9.1
1.9.0
1.8.1
1.8.0
1.7.1
1.7.0
1.6.0
1.5.0
1.4.1
1.4.0
1.3.0
1.2.1
1.2.0
1.1.3
1.1.2
1.1.1
1.1.0
1.0.0
0.9.1
0.9.0
0.8.0
0.6.0
0.5.0
0.3.0
0.2.0
Vulnerabilities (4)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU137320 - Origin Validation Error CVE-2026-59950 |
CWE-346 | High | 1.28.1 | 10.07.2026 |
SB2026071043 |
||
| #VU120189 - Insecure Default Initialization of Resource CVE-2025-66416 |
CWE-1188 | Low | 1.23.0 | 18.12.2025 |
SB2025121831 SB2025121832 SB2026041041 and 1 more |
||
| #VU120188 - Uncaught Exception CVE-2025-53365 |
CWE-248 | Medium | 1.10.0 | 18.12.2025 |
SB2025121828 SB2026011659 |
||
| #VU120187 - Uncaught Exception CVE-2025-53366 |
CWE-248 | Medium | 1.9.4 | 18.12.2025 |
SB2025121827 SB2026011659 |