Insecure Default Initialization of Resource in typescript-sdk - CVE-2025-66414
Published: March 11, 2026
Vulnerability details
The vulnerability allows a remote attacker to read and modify data on the system.
The vulnerability exists due to Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default for HTTP-based servers. A remote attacker can invoke tools or access resources exposed by the MCP server on behalf of the user in limited circumstances.
Affected software
watsonx Orchestrate Developer Edition
How to mitigate CVE-2025-66414
watsonx Orchestrate Developer Edition - update to 2.3.0