MCP SDKs patch cross-origin redirects and experimental task session leak
MCP’s TypeScript and Python SDKs shipped three Oct 2 advisories: HTTP clients followed cross-origin redirects with custom headers and OAuth bodies (upgrade to sdk 1.32.0, client 2.3.0, or mcp 1.30.0/2.2.0), and experimental InMemoryTaskStore let clients share list/read/cancel across sessions (CVSS 8.6). None have CVEs yet, and npm audit / OSV still report zero findings.