Eigen RadarAI
Analysis

MCP SDK fixes access to another client’s experimental tasks

The Model Context Protocol TypeScript SDK has fixed a session-isolation flaw in experimental tasks on shared HTTP servers. A client could list another session’s tasks, retrieve results or cancel work when sessions used the same task store. Version 1.32.0 ties access to the creating session; the advisory’s exposure conditions exclude deployments without shared experimental task storage.

Artificial Intelligence··Evening
An upright white server and a low teal server connect through separate cables to an olive network appliance behind them on a white development worktop.

Shared task storage exposed other sessions’ work

The Model Context Protocol TypeScript SDK has fixed missing session-ownership checks in its experimental task feature. This software development kit supports applications using the protocol to connect AI tools. On an HTTP server where sessions shared a task store, one client could list another session’s tasks, read results or cancel operations. The corrected release is version 1.32.0.[1], [2]

Exposure depends on a shared experimental store

Affected first-series releases run from 1.24.0 to versions before 1.32.0. The second major series is not affected by this advisory. Exposure requires a server serving multiple clients with the taskStore feature enabled and its storage shared between sessions. Reusing the same InMemoryTaskStore instance is one configuration identified in the notice. Tasks track the status and results of long-running operations, so the missing checks cover results and cancellation as well as listing.[1]

The fix binds each task to its creating session

The revised release binds task ownership to the creating session and blocks access from other sessions. A client opening a new session does not automatically inherit tasks from its previous one. The advisory offers removal of the shared task store or separate stores for each session as temporary mitigations. Experimental task support had been marked deprecated on July twenty-eight; the notice recommends a redesigned extension approach in its place.[1]

References

  1. News sourceModel Context ProtocolMCP TypeScript SDK fixes cross-session access to task storage↩1↩2↩3
  2. News sourceThe LoopMCP TypeScript SDK fixes cross-session task access↩