Insecure Default Initialization of Resource in typescript-sdk - CVE-2025-66414

 

Insecure Default Initialization of Resource in typescript-sdk - CVE-2025-66414

Published: March 11, 2026


Vulnerability identifier: #VU123885
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-66414
CWE-ID: CWE-1188
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to read and modify data on the system.

The vulnerability exists due to Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default for HTTP-based servers. A remote attacker can invoke tools or access resources exposed by the MCP server on behalf of the user in limited circumstances.


Affected software

typescript-sdk
watsonx Orchestrate Developer Edition

How to mitigate CVE-2025-66414

Install updates from vendor's website.

typescript-sdk - update to 1.24.0
watsonx Orchestrate Developer Edition - update to 2.3.0

External References

Related Security Bulletins