Skip to content

Conversation

@jussi-sa
Copy link
Contributor

@jussi-sa jussi-sa commented Jan 29, 2026

Description

  • Update @modelcontextprotocol/sdk from 1.17.5 to 1.25.3 to fix ReDoS vulnerability CVE-2026-0621
  • Migrate deprecated resource API calls to new SDK methods
  • Fixes TypeScript compilation errors introduced by SDK update
  • Adds patch system to make output schema validation non-fatal

Testing

Claude Code:

Screenshot 2026-01-29 at 19 23 15

Claude Desktop:

Screenshot 2026-01-29 at 19 14 44

Cursor had an issue:

Screenshot 2026-01-29 at 19 12 26

Which is now fixed by introducing missing properties. Cursor has a strict validation of schemas, so the passthrough() doesn't fix the problem - the missing properties had to be added manually.

Screenshot 2026-01-29 at 20 03 42

VSCode:

Screenshot 2026-01-29 at 20 24 13 Screenshot 2026-01-29 at 20 24 04

Checklist

  • Code has been tested locally
  • Unit tests have been added or updated
  • Documentation has been updated if needed

Additional Notes

@jussi-sa jussi-sa requested a review from a team as a code owner January 29, 2026 18:25
@jussi-sa jussi-sa closed this Jan 29, 2026
@jussi-sa jussi-sa reopened this Jan 29, 2026
@jussi-sa jussi-sa merged commit ad24eab into main Jan 30, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants