- Notifications
You must be signed in to change notification settings - Fork 11.9k
Labels
area: @angular/clifreq1: lowOnly reported by a handful of users who observe it rarelyOnly reported by a handful of users who observe it rarelyseverity6: securitytype: bug/fix
Description
Command
version
Is this a regression?
- Yes, this behavior used to work in the previous version
The previous version in which this bug was not present was
No response
Description
Security Vulnerability Report
High Severity: DNS Rebinding Protection Disabled by Default
Package: @modelcontextprotocol/sdk
Issue: Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
Vulnerable versions: <1.24.0
Patched versions: >=1.24.0
Dependency Path:
packages__samples__angular > @angular/cli > @modelcontextprotocol/sdk More information: [GitHub Advisory GHSA-w48q-cv73-mx4w](GHSA-w48q-cv73-mx4w)
Recommended Action
Update @modelcontextprotocol/sdk to version 1.24.0 or later to resolve this vulnerability.
Minimal Reproduction
pnpm audit
Exception or Error
Your Environment
- Anything else relevant?
No response
jase88, EinfachHans, jpmartins-ca and SchroederSteffen
Metadata
Metadata
Assignees
Labels
area: @angular/clifreq1: lowOnly reported by a handful of users who observe it rarelyOnly reported by a handful of users who observe it rarelyseverity6: securitytype: bug/fix