Commit 7edbeb9
fix: upgrade @modelcontextprotocol/sdk to 1.29.0 to fix CVE-2026-4926
Upgrades @modelcontextprotocol/sdk from ^1.27.1 to ^1.29.0, which
resolves path-to-regexp to 8.4.1 and fixes the ReDoS vulnerability
GHSA-j3q9-mxjg-w52f (CVE-2026-4926).
Regenerates the patch for SDK 1.29.0 (replaces patch for 1.27.1) to
maintain the warn-instead-of-throw behavior for output schema validation.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>1 parent f08978d commit 7edbeb9
3 files changed
Lines changed: 29 additions & 11 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
51 | 51 | | |
52 | 52 | | |
53 | 53 | | |
54 | | - | |
| 54 | + | |
55 | 55 | | |
56 | 56 | | |
57 | 57 | | |
| |||
Lines changed: 21 additions & 3 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | | - | |
2 | | - | |
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
3 | 21 | | |
4 | 22 | | |
5 | | - | |
| 23 | + | |
6 | 24 | | |
7 | 25 | | |
8 | 26 | | |
| |||
0 commit comments