SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityDeferred

CVE-2025-53366

The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP).

HIGH 8.7EPSS 7.26%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (7.26%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to version 1.9.4, a validation error in the MCP SDK can cause an unhandled exception when processing malformed requests, resulting in service unavailability (500 errors) until manually restarted. Impact may vary depending on the deployment conditions, and presence of infrastructure-level resilience measures. Version 1.9.4 contains a patch for the issue.

CVSS 4.0
8.7 HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
EPSS
7.26% probability · 94th percentile
CISA KEV
Not listed
Weakness
CWE-248
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.