Skip to content

deps: bump @modelcontextprotocol/sdk from 1.25.3 to 1.27.1 in the production-dependencies group - #53

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-890f4f2061
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-890f4f2061

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Mar 2, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the production-dependencies group with 1 update: @modelcontextprotocol/sdk.

Updates @modelcontextprotocol/sdk from 1.25.3 to 1.27.1

Release notes

Sourced from @​modelcontextprotocol/sdk's releases.

v1.27.1

What's Changed

New Contributors

Full Changelog: modelcontextprotocol/typescript-sdk@v1.27.0...v1.27.1

v1.27.0

What's Changed

New Contributors

Full Changelog: modelcontextprotocol/typescript-sdk@v1.26.0...v1.27.0

v1.26.0

Addresses "Sharing server/transport instances can leak cross-client response data" in this GHSA GHSA-345p-7cg4-v4c7

What's Changed

New Contributors

Full Changelog: modelcontextprotocol/typescript-sdk@v1.25.3...v1.26.0

Commits
  • 4faa8c8 chore: bump version to 1.27.1 (#1581)
  • 09a85a8 fix: call onerror for silently swallowed transport errors (#1580)
  • e79d14a fix: prevent command injection in example URL opening (v1.x backport) (#1579)
  • 342ea39 docs: comprehensive feature documentation for SEP-1730 Tier 1 (#1548)
  • 2084a22 docs: add governance documentation for SEP-1730 (#1547)
  • f2d2145 feat: implement auth/pre-registration conformance scenario (#1545)
  • 8cbc658 chore: bump version for v1.27.0 (#1541)
  • 5c16ae3 [v1.x] feat(tasks): add streaming methods for elicitation and sampling (#1528)
  • 97ab379 feat: add url property to RequestInfo interface (#1353)
  • 825e9ab feat: backport discoverOAuthServerInfo() and discovery caching to v1.x (#1533)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the production-dependencies group with 1 update: [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk).


Updates `@modelcontextprotocol/sdk` from 1.25.3 to 1.27.1
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](modelcontextprotocol/typescript-sdk@v1.25.3...v1.27.1)

---
updated-dependencies:
- dependency-name: "@modelcontextprotocol/sdk"
  dependency-version: 1.27.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Mar 2, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@robotlearning123

Copy link
Copy Markdown
Member

Independent verification of PR #53 (execution-based review)

Verified at head 26ec71c (merge-base with main ce7da5b; main has since advanced to e704b49). Local run: Node v22.22.0, npm 10.9.4.

Checks / tests at head

  • npm ci: exit 0 (327 packages) — lockfile integrity OK; diff touches only package-lock.json + packages/mcp/package.json, no workflow changes
  • Root typecheck / build / lint / format:check: all PASS
  • npm test: 57/57 pass (base origin/main@e704b49: 57/57 pass — no delta)
  • packages/mcp tsc --noEmit after root build: PASS (without root dist/ it fails TS2307 'agent-ready' identically on base and head — pre-existing workspace-order artifact, unrelated to the SDK)
  • Runtime smoke on SDK 1.27.1: stdio initialize handshake and tools/list both respond correctly

Advisory delta (npm audit: base 19 → head 20)

  • FIXED: @modelcontextprotocol/sdk high — cross-client data leak via shared server/transport instance reuse, range 1.10.0–1.25.3 (GHSA-345p-7cg4-v4c7)
  • INTRODUCED, both high, both new transitives of SDK 1.27.1 as resolved in this March-era lockfile:
    • express-rate-limit 8.2.1 (vulnerable 8.0.1–8.5.0): IPv4-mapped IPv6 addresses bypass per-client rate limiting
    • ip-address 10.0.1 (vulnerable <=10.3.0): XSS in Address6 HTML-emitting methods + leading-zero octet SSRF
  • Net: −1 high / +2 high = +1 high overall (10H/8M/1L → 11H/8M/1L)
  • Both clear under fresh resolution: express-rate-limit@8.7.0 (outside the vulnerable range) requires ip-address@^10.2.0 → 10.7.2 (outside <=10.3.0)

Delivered vs title: title says 1 update; delivered = SDK 1.25.3→1.27.1 plus in-subtree transitive changes (express-rate-limit 7.5.1→8.2.1, qs 6.14.1→6.15.0, new ip-address 10.0.1, jose and zod-to-json-schema range bumps, peer flag normalization) and a lockfile root-version drift fix (0.1.0 → matches package.json 0.2.0). Everything is confined to the SDK subtree / npm normalization — nothing unrelated.

Failing check claude-review: pre-existing repo-wide workflow breakage ("Claude execution failed: result is_error:true") — it fails on every recent branch including merges to main, so it is not attributable to this diff.

Staleness: branch created 2026-03-02 (~7 months old). Main still pins SDK 1.25.3 in the lockfile, so this PR is not superseded and no newer SDK PR exists; however 5 other open dependabot PRs (#65, #66, #68, #69, #70) touch the same lockfile, so merge order matters.

Verdict: FIX-FIRST (rebase), then merge. The code-level change is green and fixes GHSA-345p-7cg4-v4c7, but as-committed the lockfile drags in 2 new high advisories; a @dependabot rebase (maintainer action — this review lane does not rewrite foreign heads) would re-resolve both to fixed versions.

@robotlearning123

Copy link
Copy Markdown
Member

Independent cross-model review (grok headless review, execution re-verified): FIX-FIRST

The bump removes the SDK's own advisory (GHSA-345p-7cg4-v4c7, row gone from head audit) but net-adds high advisories to the dependency tree. npm audit --package-lock-only delta, same flags, base ce7da5b vs head 26ec71c:

  • plain: 10 high / 19 total -> 11 high / 20 total
  • prod-only (--omit=dev): 2 high / 2 total -> 8 high / 11 total

Findings (reproduced against the registry advisory DB):

  1. major — package-lock.json:2283 express-rate-limit 7.5.1 -> 8.2.1. 8.2.1 is inside the GHSA-46wh-pxpv-q5gq vulnerable range (npm audit: 8.0.1-8.5.0): IPv4-mapped-IPv6 clients escape the rate-limit bucket. Reachable from SDK 1.27.1's OAuth token handler, which applies rateLimit() with the default keyGenerator (node_modules/@modelcontextprotocol/sdk/dist/esm/server/auth/handlers/token.js:6,31-38; SDK dep range "express-rate-limit": "^8.2.1" at package-lock.json:844). Not exercised by the current stdio-only server (packages/mcp/src/index.ts), but the vulnerable version is what npm ci ships.
  2. major — package-lock.json:2754 ip-address newly introduced, pinned exactly 10.0.1 (dep of express-rate-limit 8.2.1). Vulnerable per GHSA-mwp4-54f8-5fhr (<=10.3.0) and GHSA-v2v4-37r5-5v8g (<=10.1.0). express-rate-limit 8.7.0 widens to ip-address@^10.2.0, which includes the fix.
  3. minor — package-lock.json:3642 qs 6.14.1 -> 6.15.0 lands inside GHSA-x5fp-wj9c-mxmq (>=6.14.2 <=6.15.3); 6.14.1 was outside it. Not directly imported by this repo.

Verified NOT broken (checked; do not re-hunt): npm ci exit 0 (lock integrity, 327 pkgs); stdio smoke on installed SDK 1.27.1 (tools/list, get_repo_context, check_repo_readiness error path, init_files default) all correct; tsc clean in packages/mcp; npm test 57/57 pass; CI Build/Lint/Test(20,22)/Type Check green at this head; lockfile root header 0.1.0 -> 0.2.0 now matches package.json (fixes a pre-existing desync on main); express stays 5.2.1; manifest floor ^1.11.0 -> ^1.27.1 matches the resolved version; no superseding dependabot PR for this package. Note: latest published SDK is 1.30.1, so this PR is also ~3 minors stale.

Suggested resolution: @dependabot rebase to refresh the lock (express-rate-limit then resolves >=8.5.1 within the SDK's ^8.2.1 range; ip-address via its range), or rebase onto SDK 1.30.x; alternatively add overrides for express-rate-limit/ip-address/qs. Do not merge as-is.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant