MCP servers bundle their own copies of vulnerable packages. After global install, patch nested node_modules in each server directly: - @modelcontextprotocol/sdk 1.0.1 → 1.25.2 (CVE-2025-66414, CVE-2026-0621) - picomatch 4.0.3 → 4.0.4 (CVE-2026-33671) Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| Dockerfile | ||
| settings.json | ||