Your MCP dependency scan can pass and still miss HIGH vulnerabilities

Your MCP dependency scan can pass and still miss HIGH vulnerabilities

Quick story, then the practical part. We scanned five official MCP reference servers from the @modelcontextprotocol npm namespace. Standard tooling against the package manifest: 0 findings Then we re-ran the same check against the installed dependency tree: 10 HIGH findings Same five servers. Same advisory database. The difference was that the second scan walked into a package the first one never had reason to query: @modelcontextprotocol/sdk@1.0.1. The advisories were public...

Original Source

Read the full article at Dev →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.