VDB

CVE-2025-66414

CVE-2025-66414 PUBLISHED CVSS 7.599999904632568 HIGH

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

EPSS 0.04% · 12.2th percentile

Risk Scores

CVSS v4.0
7.599999904632568
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS Score
0.04%
12.2th percentile

Affected Products

VendorProductVersions
lfprojectsmcp_typescript_sdk0
modelcontextprotocolsdk0
modelcontextprotocoltypescript-sdk*

Timeline

  • Dec 2, 2025 CVE Published
  • Dec 3, 2025 EPSS Score
  • Dec 7, 2025 EPSS Score
  • Dec 12, 2025 EPSS Score
  • Dec 16, 2025 EPSS Score
  • Dec 21, 2025 EPSS Score
  • Dec 25, 2025 EPSS Score
  • Dec 29, 2025 EPSS Score
  • Jan 3, 2026 EPSS Score
  • Jan 7, 2026 EPSS Score
  • Jan 11, 2026 EPSS Score
  • Jan 16, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›