← All tasks
pythonanthropics/claude-agent-sdk-python #921Not a task: already works

Tighten mcp dependency to >=1.23.0 due to CVE-2025-66416

envgap__anthropics__claude-agent-sdk-python-921

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • The project already builds and runs before the fix, so there is nothing to repair.

02 / ENVIRONMENT RECIPE

Base commit
9aafd84b008c1ca2c26bf24b5d99af762551a00d
Manifest
pyproject.toml
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

anthropics/claude-agent-sdk-python #921 · read the original issue
Hi Anthropic team,

claude-agent-sdk==0.1.73 currently declares the following dependency:

mcp>=1.19.0 (https://github.com/anthropics/claude-agent-sdk-python/blob/main/pyproject.toml#L31)

This version range allows installing mcp versions from 1.19.0 through 1.22.x.

Those versions are affected by the public advisory CVE-2025-66416 / GHSA-9h52-p55h-vw2f:

https://osv.dev/vulnerability/GHSA-9h52-p55h-vw2f

The advisory states that the MCP Python SDK did not enable DNS rebinding protection by default for HTTP-based localhost MCP servers before mcp==1.23.0.

Suggested fix:

mcp>=1.23.0

This would prevent new claude-agent-sdk installations from resolving to an affected mcp version.

Impact note: this is most relevant when applications use HTTP-based local MCP servers without authentication. So this may be best classified as dependency hardening / vulnerable dependency range rather than a direct vulnerability in claude-agent-sdk itself.

Thanks!
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]