MCP SDK fixes access to another client’s experimental tasks
The Model Context Protocol TypeScript SDK has fixed a session-isolation flaw in experimental tasks on shared HTTP servers. A client could list another session’s tasks, retrieve results or cancel work when sessions used the same task store. Version 1.32.0 ties access to the creating session; the advisory’s exposure conditions exclude deployments without shared experimental task storage.
Artificial Intelligence··Evening
Shared task storage exposed other sessions’ work
The Model Context Protocol TypeScript SDK has fixed missing session-ownership checks in its experimental task feature. This software development kit supports applications using the protocol to connect AI tools. On an HTTP server where sessions shared a task store, one client could list another session’s tasks, read results or cancel operations. The corrected release is version 1.32.0.[1], [2]
Exposure depends on a shared experimental store
Affected first-series releases run from 1.24.0 to versions before 1.32.0. The second major series is not affected by this advisory. Exposure requires a server serving multiple clients with the taskStore feature enabled and its storage shared between sessions. Reusing the same InMemoryTaskStore instance is one configuration identified in the notice. Tasks track the status and results of long-running operations, so the missing checks cover results and cancellation as well as listing.[1]
The fix binds each task to its creating session
The revised release binds task ownership to the creating session and blocks access from other sessions. A client opening a new session does not automatically inherit tasks from its previous one. The advisory offers removal of the shared task store or separate stores for each session as temporary mitigations. Experimental task support had been marked deprecated on July twenty-eight; the notice recommends a redesigned extension approach in its place.[1]