Public evidence library

Trace the claim.
Open the source.

This is the research spine of MCP Blog: 285 canonical records spanning the protocol’s technical roots, public history, specifications, ecosystem, governance, security, and current host documentation.

285Total records
121Durable sources
132Require live checks
118Official MCP project sources

Search the corpus

Every evidence record

285 sources shown

Durable — historical or normative source unlikely to change

Live check — current-state claim must be reverified before reuse

Periodic — stable enough to cite, but worth scheduled review

Review status: Durable. S001
STANDARD2010-03-26Version 2.0Primary standard

JSON-RPC 2.0 Specification

JSON-RPC Working Group

Supports: Defines requests, responses, notifications, errors, and batching used by MCP. Requests, responses, notifications, errors and transport independence. Request, response, notification, error and transport-agnostic RPC semantics Request, response, notification and error object semantics used by MCP.

Review status: Durable. S002
DOCUMENTATION2016-06-27

Language Server Protocol Overview

Microsoft

Supports: Primary architectural background for editor-client/language-server reuse and JSON-RPC capability negotiation.

Review status: Live check required. S007
INTERNET-DRAFTLIVE

OAuth 2.1 Internet-Draft

IETF OAuth WG

Supports: Status and evolving basis of MCP authorization framework.

Review status: Durable. S009
BLOG2023-03-23

ChatGPT plugins

OpenAI

Supports: Pre-MCP vendor plugin architecture using manifests, APIs, and OAuth. Earlier vendor-specific plugin model using manifests, OpenAPI and OAuth.

Review status: Durable. S010
BLOG2023-06-13Primary vendor

Function calling and other API updates

OpenAI

Supports: Pre-MCP model function-calling history. Pre-MCP function-calling history and structured model action selection. Public OpenAI function-calling introduction, JSON arguments and early security warning

Review status: Live check required. S011
DOCUMENTATIONLIVEPrimary vendor

Tool use with Claude

Anthropic

Supports: Distinguishes vendor tool-use APIs from MCP interoperability. Client versus server tools and structured tool_use behavior

Review status: Durable. S013
GIT COMMIT2024-09-24Version early draft

Initial import of MCP specification repository

Model Context Protocol

Supports: Earliest public commit; states LSP inspiration, host/client/server/session terminology, resources, prompts, tools, sampling, stdio and SSE. Earliest public repository evidence and explicit LSP inspiration.

Review status: Durable. S015
GIT COMMIT2024-09-24

Initial Python SDK import

Model Context Protocol

Supports: Earliest public Python SDK evidence.

Review status: Durable. S018
GIT REPOSITORY2024-11-19

Reference servers repository

Model Context Protocol

Supports: Repository creation and evolution of reference servers.

Review status: Durable. S019
GIT COMMIT2024-11-19

Initial reference servers commit

Model Context Protocol

Supports: First public reference-server monorepo commit. Earliest verified public reference server set.

Review status: Durable. S020
GIT TREE2024-11-19

Initial reference-server repository tree

Model Context Protocol

Supports: Confirms initial public directories including everything, Google Drive, Git, Postgres, and Puppeteer.

Review status: Durable. S021
BLOG2024-11-25Version LaunchPrimary vendor

Introducing the Model Context Protocol

Anthropic

Supports: Public launch, creators, SDKs, Claude Desktop support, example integrations, and stated integration problem. Public announcement, integration-fragmentation rationale, SDKs, Claude Desktop and example servers. MCP public announcement, integration-fragmentation rationale, initial SDK and host context Public launch, initial local-first integration rationale, initial SDK and host context

Review status: Durable. S022
BLOG2024-11-25

Zed and the Model Context Protocol

Zed Industries

Supports: Launch-day non-Anthropic host integration and explicit LSP comparison. Zed launch-day MCP integration and collaboration with Anthropic.

Review status: Live check required. S023
READMELIVE

Model Context Protocol repository README

Model Context Protocol

Supports: Current creator credit to David Soria Parra and Justin Spahr-Summers. Official creator credit for David Soria Parra and Justin Spahr-Summers.

Review status: Durable. S024
SPEC2024-11-05Version 2024-11-05Authoritative specification

MCP specification 2024-11-05

Model Context Protocol

Supports: Authoritative launch-era specification overview. Launch-era stateful architecture, initialization, stdio, HTTP+SSE and original capabilities. Initial released protocol overview and date-based revision Launch-era architecture, lifecycle, capabilities and trust guidance

Review status: Durable. S025
SPEC2024-11-05Version 2024-11-05Authoritative specification

Architecture 2024-11-05

Model Context Protocol

Supports: Launch-era host/client/server architecture. Launch-era host, client, server, JSON-RPC and stateful-session architecture

Review status: Durable. S026
SPEC2024-11-05Version 2024-11-05

Lifecycle 2024-11-05

Model Context Protocol

Supports: Initialize/initialized handshake, version and capability negotiation. Launch-era initialize/initialized lifecycle and capability negotiation.

Review status: Durable. S027
SPEC2024-11-05Version 2024-11-05Authoritative specification

Transports 2024-11-05

Model Context Protocol

Supports: stdio and HTTP+SSE semantics. Original stdio and HTTP+SSE transport behavior Original stdio and HTTP+SSE transport semantics

Review status: Durable. S028
SPEC2024-11-05Version 2024-11-05Authoritative specification

Tools 2024-11-05

Model Context Protocol

Supports: Launch-era tool listing and invocation. Launch-era tool definition and model-controlled interaction guidance Launch-era tool discovery, invocation and human-control guidance

Review status: Durable. S029
SPEC2024-11-05Version 2024-11-05Authoritative specification

Resources 2024-11-05

Model Context Protocol

Supports: URI-addressed resources, templates, and subscriptions. Launch-era resource semantics Launch-era resources, subscriptions and data exposure semantics

Review status: Durable. S030
SPEC2024-11-05Version 2024-11-05Authoritative specification

Prompts 2024-11-05

Model Context Protocol

Supports: Server-exposed prompt templates and user-controlled workflows. Launch-era prompt-template semantics

Review status: Durable. S031
SPEC2024-11-05Version 2024-11-05

Roots 2024-11-05

Model Context Protocol

Supports: Client-declared filesystem/project boundaries.

Review status: Durable. S032
SPEC2024-11-05Version 2024-11-05Authoritative specification

Sampling 2024-11-05

Model Context Protocol

Supports: Server requests model sampling through client/host. Launch-era server-to-client sampling and user-control expectations

Review status: Durable. S033
SPEC2024-11-05Version 2024-11-05

Logging 2024-11-05

Model Context Protocol

Supports: Protocol logging method and notifications.

Review status: Durable. S034
SPEC2024-11-05Version 2024-11-05

Completion 2024-11-05

Model Context Protocol

Supports: Argument-completion utility present at launch.

Review status: Durable. S036
CHANGELOG2025-03-26Version 2025-03-26Authoritative specification

Key changes 2025-03-26

Model Context Protocol

Supports: OAuth framework, Streamable HTTP, batching, tool annotations, audio, progress, completions capability. OAuth-based authorization, Streamable HTTP, JSON-RPC batching, tool annotations, audio, progress text and completions capability entered the released specification. OAuth framework, Streamable HTTP, batching, annotations, audio and completions Initial authorization framework, Streamable HTTP, annotations and batching Streamable HTTP, OAuth framework, batching and tool annotations.

Review status: Durable. S037
SPEC2025-03-26Version 2025-03-26Authoritative specification

Authorization 2025-03-26

Model Context Protocol

Supports: First protocol authorization framework. Initial OAuth-oriented remote authorization framework First protocol authorization framework for HTTP deployments

Review status: Durable. S038
SPEC2025-03-26Version 2025-03-26

Streamable HTTP 2025-03-26

Model Context Protocol

Supports: Original Streamable HTTP, stateful session, optional SSE, backwards compatibility. Original Streamable HTTP semantics, including POST/GET, optional SSE, resumability and optional Mcp-Session-Id session management.

Review status: Durable. S041
PR2025-03-26Version 2025-03-26

PR #185: Tool annotations

Model Context Protocol

Supports: Origin of read-only, destructive, idempotent, and open-world hints.

Review status: Durable. S043
CHANGELOG2025-06-18Version 2025-06-18Authoritative specification

Key changes 2025-06-18

Model Context Protocol

Supports: Batching removal, structured output, resource-server classification, Resource Indicators, elicitation, resource links. JSON-RPC batching was removed; structured tool output, resource links, elicitation and authorization hardening were added. Batching removal, structured output, elicitation and authorization hardening Resource-server classification, protected-resource metadata, Resource Indicators and structured output Removal of batching, structured tool output, elicitation and authorization hardening.

Review status: Durable. S044
SPEC2025-06-18Version 2025-06-18Authoritative specification

Authorization 2025-06-18

Model Context Protocol

Supports: OAuth resource-server model, protected resource metadata, PKCE, Resource Indicators. Resource Indicators, token audience validation and resource-server model Audience restrictions, protected resource metadata and token validation

Review status: Durable. S045
SPEC2025-06-18Version 2025-06-18Authoritative specification

Tools 2025-06-18

Model Context Protocol

Supports: Structured tool output and output schema. Structured tool output and outputSchema semantics

Review status: Durable. S046
SPEC2025-06-18Version 2025-06-18

Elicitation 2025-06-18

Model Context Protocol

Supports: Server-initiated user information request capability.

Review status: Durable. S047
SPEC2025-06-18Version 2025-06-18

Security best practices 2025-06-18

Model Context Protocol

Supports: Token passthrough, confused deputy, least privilege, and proxy risks.

Review status: Durable. S049
CHANGELOG2025-11-25Version 2025-11-25Authoritative specification

Key changes 2025-11-25

Model Context Protocol

Supports: OIDC discovery, icons, incremental scopes, URL elicitation, sampling tools, client metadata documents, experimental tasks, governance. OIDC discovery, icon metadata, incremental scope consent, richer elicitation, CIMD, tool use in sampling and experimental Tasks entered the released specification. One-year revision changes including experimental Tasks OIDC discovery, CIMD, incremental consent, URL elicitation and experimental Tasks OIDC discovery, CIMD, expanded elicitation, experimental Tasks and governance changes.

Review status: Durable. S050
SPEC2025-11-25Version 2025-11-25

Tasks 2025-11-25

Model Context Protocol

Supports: Experimental core Tasks semantics.

Review status: Durable. S053
RELEASE CANDIDATE2026-05-21Version 2026-07-28-rcOfficial project

The 2026-07-28 specification release candidate

Model Context Protocol

Supports: RC chronology and rationale for stateless core, extensions, tasks, apps, and deprecation. RC date, validation window, motivations and distinction between RC and GA. RC chronology and technical motivation for stateless architecture Infrastructure motivation for statelessness, routing and caching Release-candidate chronology and before/after architecture rationale.

Review status: Live check required. S054
SPEC2026-07-28Version 2026-07-28

MCP specification 2026-07-28

Model Context Protocol

Supports: Current authoritative specification at verification date. Current authoritative protocol overview, roles, JSON-RPC basis, primitives, security principles.

Review status: Durable. S055
CHANGELOG2026-07-28Version 2026-07-28Authoritative specification

Key changes 2026-07-28

Model Context Protocol

Supports: Stateless core, discovery, MRTR, subscriptions/listen, routing headers, caching, tasks extension, deprecations. Removal of handshake and sessions; discovery, subscriptions, routing, caching, extensions and deprecations. Canonical list of 2026 additions, removals, deprecations and compatibility effects Stateless core, removal of sessions and initialization, routing headers, cache scope, auth hardening, MRTR and deprecations Removal of initialize, initialized, protocol sessions and Mcp-Session-Id; addition of server/discover, MRTR, routing headers and cacheable results.

Review status: Durable. S056
SPEC2026-07-28Version 2026-07-28Authoritative specification

Versioning and compatibility 2026-07-28

Model Context Protocol

Supports: Modern/legacy/dual-era compatibility and per-request versioning. Current version declaration and compatibility behavior Per-request version declaration, modern versus legacy eras, discovery and dual-era compatibility.

Review status: Durable. S057
SPEC2026-07-28Version 2026-07-28Authoritative specification

Transports overview 2026-07-28

Model Context Protocol

Supports: Current transport bindings and no server-initiated JSON-RPC requests in modern core. Current stdio and Streamable HTTP semantics Current sessionless HTTP transport and request header rules Transport is separate from protocol semantics; current stdio and Streamable HTTP transports.

Review status: Periodic review. S058
BLOG2026-07-28Version 2026-07-28Official project

The 2026-07-28 Specification

Model Context Protocol

Supports: GA announcement, SDK support, architecture rationale, download claims. GA announcement and maintainer explanation of the stateless revision. GA release, stateless core, MRTR, routing, caching, auth and extensions Maintainer explanation of the current release GA announcement and maintainers’ explanation of stateless architecture, discovery, MRTR, caching and extensions.

Review status: Durable. S059
EXTENSION2026-01-26Version io.modelcontextprotocol/uiOfficial project

MCP Apps: Bringing UI capabilities to MCP clients

Model Context Protocol

Supports: First official extension; sandboxed server-provided UI. Launch of the first official MCP extension and historical context. MCP Apps origin and server-provided UI concept

Review status: Durable. S060
SEP2026-07-28Version io.modelcontextprotocol/tasks

SEP-2663: Tasks extension

Model Context Protocol

Supports: Tasks moved from experimental core to official extension. Migration of Tasks from experimental core into an official extension.

Review status: Durable. S061
SEP2026-07-28Version 2026-07-28

SEP-2575: Stateless protocol

Model Context Protocol

Supports: Removal of handshake/sessions and per-request metadata model. Motivation and proposal history for removing initialization state.

Review status: Live check required. S064
ROADMAP2026-08-22Version Post-2026-07-28Official project blog

The New MCP Roadmap

Model Context Protocol

Supports: Post-2026-07-28 priorities; proposals, not shipped features. Current roadmap priorities; proposals are not shipped features. Agent identity, enterprise-ready security and HTTP hardening priorities Current roadmap and retrospective confirmation of session and handshake removal.

Review status: Durable. S066
REGISTRY2025-09-08Version Registry previewOfficial project blog

Introducing the MCP Registry

Model Context Protocol

Supports: Official registry preview launch and origin history. Registry launch date, preview status and collaborative origin. Registry launch, namespace verification and metadata role

Review status: Live check required. S067
REGISTRYLIVEVersion CurrentOfficial docs

The MCP Registry: About

Model Context Protocol

Supports: Current preview status, metadata role, namespaces, package-registry relationship, scanning limits. Official registry scope, metadata role, namespace verification and security-scanning limits. Registry metadata role and limits; code/package scanning delegated elsewhere

Review status: Live check required. S068
REGISTRYLIVE

MCP Registry

Model Context Protocol

Supports: Current registry endpoint.

Review status: Durable. S070
GOVERNANCE2025-12-09

MCP joins the Agentic AI Foundation

Model Context Protocol

Supports: Donation to AAIF, technical autonomy, project-reported adoption statistics. MCP's Linux Foundation/AAIF organizational home and retained technical governance.

Review status: Live check required. S071
GOVERNANCELIVE

Governance and stewardship

Model Context Protocol

Supports: Current lead/core maintainer structure and LF project status. Current maintainer structure and individual rather than corporate membership.

Review status: Live check required. S073
GOVERNANCE2026-02-23

SDK Tiering System

Model Context Protocol

Supports: Tier 1–3 requirements and conformance-based governance. Meaning of SDK tiers and maintenance/conformance expectations.

Review status: Live check required. S075
SDK2024-11-25

TypeScript SDK repository

Model Context Protocol

Supports: Official launch SDK; current status live-check.

Review status: Live check required. S076
SDK2024-11-25

Python SDK repository

Model Context Protocol

Supports: Official launch SDK; current status live-check.

Review status: Live check required. S077
SDKLIVE

Go SDK repository

Model Context Protocol

Supports: Official SDK status and history.

Review status: Live check required. S078
SDKLIVE

C# SDK repository

Model Context Protocol

Supports: Official SDK status and history.

Review status: Live check required. S079
SDKLIVE

Java SDK repository

Model Context Protocol

Supports: Official SDK status and history.

Review status: Live check required. S080
SDKLIVE

Kotlin SDK repository

Model Context Protocol

Supports: Official SDK status and history.

Review status: Live check required. S081
SDKLIVE

Rust SDK repository

Model Context Protocol

Supports: Official SDK status and history.

Review status: Live check required. S082
SDKLIVE

Swift SDK repository

Model Context Protocol

Supports: Official SDK status and history.

Review status: Live check required. S083
SDKLIVE

Ruby SDK repository

Model Context Protocol

Supports: Official SDK status and history.

Review status: Live check required. S086
SDKLIVE

PHP SDK repository

Model Context Protocol

Supports: Current official PHP SDK status.

Review status: Durable. S088
VENDOR ADOPTION2025-05-14

Beyond the tools, adding MCP in VS Code

Microsoft / Visual Studio Code

Supports: Expansion from tools toward richer capabilities and installation UX. VS Code host behavior, tool picker and server integration.

Evidence note: First-party product documentation rechecked and normalized on 2026-08-25; the package URL remains in the package source map.

Review status: Durable. S089
VENDOR ADOPTION2025-05-21Primary vendor

New tools and features in the Responses API

OpenAI

Supports: First unequivocal official remote MCP support in OpenAI API product. Official remote MCP support in the Responses API. First official OpenAI remote MCP support announcement

Review status: Live check required. S090
VENDOR DOCUMENTATIONLIVEOfficial SDK

Model Context Protocol in the OpenAI Agents SDK

OpenAI

Supports: Current hosted, Streamable HTTP, SSE, and stdio MCP integration modes. MCP schema conversion, name prefixing, hosted/local transport, filtering, approvals and caching Hosted, Streamable HTTP, legacy SSE and stdio MCP client options; manager for multiple servers.

Review status: Durable. S092
VENDOR ADOPTION2025-04-22

MCP Toolbox for Databases supports MCP

Google Cloud

Supports: Official Google Cloud server/platform support. Official Google Cloud MCP server/platform adoption.

Review status: Periodic review. S096
VENDOR ADOPTION2025-05-01

MCP Demo Day

Cloudflare and vendors

Supports: Remote servers from multiple SaaS vendors; useful but partly promotional.

Review status: Live check required. S100
VENDOR DOCUMENTATIONLIVE

Cursor MCP documentation

Cursor

Supports: Current host support; first historical date remains separately qualified.

Review status: Live check required. S103
VENDOR DOCUMENTATIONLIVE

Notion MCP documentation

Notion

Supports: Official Notion server documentation; current state live-check.

Review status: Live check required. S104
FRAMEWORKLIVE

LangChain MCP adapters

LangChain

Supports: Framework adapter demonstrating MCP-to-native-tool mapping.

Review status: Live check required. S107
FRAMEWORKLIVE

AutoGen MCP Workbench

Microsoft

Supports: MCP integration in AutoGen.

Review status: Durable. S108
SECURITY2025-04-01Version Session-era clientsOriginal research

MCP Security Notification: Tool Poisoning Attacks

Invariant Labs

Supports: Canonical disclosure of hidden tool-description attacks, rug pulls, and tool shadowing. Original tool-poisoning, rug-pull and cross-server-shadowing research. Original public disclosure of tool poisoning, shadowing and rug-pull patterns

Review status: Durable. S109
SECURITY ADVISORY2025-06-13Version <0.14.1Vendor advisory / CVE

MCP Inspector missing authentication

Model Context Protocol

Supports: Inspector proxy exposure; implementation vulnerability, not core-protocol semantics. Representative host/developer-tool implementation vulnerability. Remote code execution due to unauthenticated Inspector proxy; patched/fixed status: 0.14.1

Evidence note: Layer: Host/developer tool. Verify current affected and fixed ranges before publication.

Review status: Durable. S110
SECURITY ADVISORY2025-09-06Version <0.16.6Vendor advisory / CVE

MCP Inspector XSS advisory

Model Context Protocol

Supports: Inspector implementation vulnerability with potential command-execution path. Representative Inspector UI vulnerability and patch boundary. Cross-site scripting in Inspector; patched/fixed status: 0.16.6

Evidence note: Layer: Host/developer tool. Verify current affected and fixed ranges before publication.

Review status: Durable. S111
SECURITY ADVISORY2025-12-02Version <1.24.0Vendor advisory / CVE

TypeScript SDK DNS rebinding advisory

Model Context Protocol

Supports: HTTP SDK default-binding risk; stdio unaffected. Representative local HTTP SDK exposure and Origin/bind protection. DNS rebinding protection disabled by default for unauthenticated localhost HTTP servers; patched/fixed status: 1.24.0

Evidence note: Layer: SDK/transport. Verify current affected and fixed ranges before publication.

Review status: Durable. S112
SECURITY ADVISORY2025-12-02Version <1.23.0Vendor advisory / CVE

Python SDK DNS rebinding advisory

Model Context Protocol

Supports: Python HTTP SDK default-binding risk. Representative Python SDK DNS-rebinding vulnerability. DNS rebinding protection disabled by default for localhost HTTP servers; patched/fixed status: 1.23.0

Evidence note: Layer: SDK/transport. Verify current affected and fixed ranges before publication.

Review status: Durable. S121
SPEC2026-07-28Version 2026-07-28

Architecture 2026-07-28

Model Context Protocol

Supports: Current host, client, server definitions; one client per server; stateless per-request model. Current host, client, and server definitions; one host manages multiple clients; each client relates to one server; stateless per-request architecture.

Review status: Durable. S122
DOCUMENTATION2026-07-28Version 2026-07-28

MCP Architecture Guide

Model Context Protocol

Supports: Conceptual architecture, data and transport layers, local and remote servers.

Review status: Durable. S123
SPEC2026-07-28Version 2026-07-28Authoritative specification

Tools

Model Context Protocol

Supports: Tool discovery, schemas, invocation, result content, structured output, annotations and security rules. Current tool schemas, calls, results, annotations and state-handle guidance Current tool semantics, annotations, schemas, explicit handles and security considerations Tool discovery and invocation, host human-in-the-loop guidance, annotations, explicit handles and MRTR.

Review status: Durable. S124
SPEC2026-07-28Version 2026-07-28Authoritative specification

Resources

Model Context Protocol

Supports: URI-identified resources, list/read/templates and subscriptions behavior. Current resource primitive Server-exposed resources, URI identification, list/read behavior and subscriptions.

Review status: Durable. S125
SPEC2026-07-28Version 2026-07-28Authoritative specification

Prompts

Model Context Protocol

Supports: Protocol-exposed prompt templates, arguments, list/get behavior and user control. Current prompt primitive Server-exposed prompt templates and host presentation.

Review status: Durable. S126
SPEC2026-07-28Version 2026-07-28

Elicitation

Model Context Protocol

Supports: Server requests for user input, form and URL modes, restrictions on sensitive data. Current client-side elicitation through MRTR and host-controlled user interaction.

Review status: Durable. S127
SPEC2026-07-28Version 2026-07-28Authoritative specification

Server discovery

Model Context Protocol

Supports: Mandatory server/discover implementation and optional client invocation for versions and capabilities. Optional sessionless capability and version discovery server/discover semantics, supported versions and capabilities, optional client use, self-reported identity caveat.

Review status: Durable. S128
SPEC2026-07-28Version 2026-07-28

Caching

Model Context Protocol

Supports: Cache hints and scope for complete list/read/discovery results.

Review status: Durable. S129
SPEC2026-07-28Version 2026-07-28

Multi Round-Trip Requests

Model Context Protocol

Supports: Current mechanism for additional client input without server-initiated JSON-RPC requests.

Review status: Durable. S130
SPEC2026-07-28Version 2026-07-28Authoritative specification

Base protocol overview

Model Context Protocol

Supports: JSON-RPC messages, current statelessness, explicit state identifiers and authorization applicability. Current JSON-RPC base messages and request metadata JSON-RPC basis, current message directions, requests, responses, notifications and result types.

Review status: Durable. S131
SPEC2026-07-28Version 2026-07-28

Streamable HTTP

Model Context Protocol

Supports: Current remote transport, one POST endpoint, optional request-scoped SSE, routing headers and security. Current single-endpoint HTTP behavior, removal of GET stream and protocol sessions, request-scoped SSE, Origin requirements.

Review status: Durable. S132
SPEC2026-07-28Version 2026-07-28

stdio transport

Model Context Protocol

Supports: Local subprocess transport, newline-delimited JSON-RPC and stdout/stderr requirements. Local subprocess lifecycle, stdin/stdout framing, stderr logging, shutdown and restart behavior.

Review status: Durable. S133
SPEC2026-07-28Version 2026-07-28Authoritative specification

Authorization

Model Context Protocol

Supports: Current HTTP authorization framework, OAuth resource-server roles, protected resource metadata and resource indicators. Current HTTP authorization roles, metadata, issuer validation, Resource Indicators, token handling and CIMD preference

Review status: Periodic review. S134
SECURITY GUIDANCELIVE; verified 2026-08-25Version 2026-07-28Official project

Security Best Practices

Model Context Protocol

Supports: Confused deputy, token passthrough, SSRF, state handles, stdio proxy, redirect and issuer security. Layered security guidance, token handling and deployment risks Current official guidance on confused deputy, token passthrough, SSRF, local servers, state handles and OAuth URLs

Review status: Durable. S135
SPEC2026-07-28Version 2026-07-28

Deprecated Features

Model Context Protocol

Supports: Roots, sampling, logging, DCR and HTTP+SSE deprecation status and migration paths.

Review status: Periodic review. S136
EXTENSIONLIVE; verified 2026-08-25Version io.modelcontextprotocol/uiAuthoritative extension docs

MCP Apps

Model Context Protocol

Supports: Interactive HTML interfaces, tool-linked UI resources, sandbox and host support variability. Server-provided interactive UI, sandboxing and host security boundary

Review status: Periodic review. S137
EXTENSIONLIVE; verified 2026-08-25Version io.modelcontextprotocol/tasksAuthoritative extension docs

Tasks

Model Context Protocol

Supports: Durable asynchronous operations, task IDs, polling, input and cancellation semantics. Long-running task handles and lifecycle semantics

Review status: Live check required. S138
SDK INDEXLIVE; verified 2026-08-25Version Current

Official MCP SDKs

Model Context Protocol

Supports: Current official SDK list and tier assignments.

Review status: Periodic review. S139
DOCUMENTATIONLIVEVersion Current

Language Server Extension Guide

Microsoft

Supports: LSP client/server architecture and the M × N integration problem.

Review status: Live check required. S140
VENDOR DOCUMENTATIONLIVE; verified 2026-08-25Version Current

Developer mode and MCP apps in ChatGPT

OpenAI

Supports: Current ChatGPT remote MCP limitations, local-server tunnel requirement and plan-dependent access. ChatGPT as a host with remote MCP connector support and MCP Apps; current availability and remote-only direct connection constraints.

Evidence note: First-party product documentation rechecked and normalized on 2026-08-25; the package URL remains in the package source map.

Review status: Live check required. S141
VENDOR DOCUMENTATIONLIVE; verified 2026-08-25Version Current

Add and manage MCP servers in VS Code

Microsoft / Visual Studio Code

Supports: Current local/remote installation, trust, sandboxing, prompts/resources/apps and enterprise policy support. VS Code host/client support for tools, resources, prompts and MCP Apps; local and remote servers, trust and policy.

Evidence note: First-party product documentation rechecked and normalized on 2026-08-25; the package URL remains in the package source map.

Review status: Live check required. S144
VENDOR DOCUMENTATION2026-06-18Version Current

MCP servers with Gemini CLI

Google

Supports: Gemini CLI support for stdio, legacy SSE and Streamable HTTP, tools/resources/prompts, OAuth and confirmations. Gemini CLI local and remote MCP support and host permission flow.

Evidence note: First-party product documentation rechecked and normalized on 2026-08-25; the package URL remains in the package source map.

Review status: Live check required. S145
VENDOR DOCUMENTATIONLIVE; verified 2026-08-25Version Current

Get started with custom connectors using remote MCP

Anthropic

Supports: Claude custom remote MCP connector availability and trust cautions. Claude remote connector behavior and cloud-originated connections.

Review status: Live check required. S146
VENDOR DOCUMENTATIONLIVE; verified 2026-08-25Version Current

Use connectors to extend Claude's capabilities

Anthropic

Supports: Remote connectors connect from Anthropic cloud and product terminology differs from protocol roles.

Review status: Durable. S147
SECURITY ADVISORY2026Version TypeScript SDK 1.10.0–1.25.3Vendor advisory / CVE

TypeScript SDK cross-client data leak

GitHub Advisory Database

Supports: Representative multi-client isolation implementation defect. Cross-client response data leakage when server/transport instances are reused; patched/fixed status: 1.26.0

Evidence note: Layer: SDK/multi-tenancy. Verify current affected and fixed ranges before publication.

Review status: Periodic review. S148
SEO GUIDANCE2025-12-10Version CurrentPrimary search-engine guidance

Creating helpful, reliable, people-first content

Google Search Central

Supports: People-first, original, well-sourced content and no preferred word count. People-first, original, trustworthy content and authorship guidance People-first content, no preferred word count, authorship/process transparency and satisfying user intent.

Review status: Periodic review. S150
SEO GUIDANCE2025-12-10Version Current

Influencing your title links in search results

Google Search Central

Supports: Descriptive, concise and consistent title/H1 recommendations. Descriptive concise titles, distinctive H1 and avoidance of keyword stuffing.

Review status: Periodic review. S152
SEO GUIDANCE2025-12-10Version CurrentPrimary search-engine guidance

Article structured data

Google Search Central

Supports: Article author, date, headline and image markup guidance. Article structured-data recommendations

Review status: Periodic review. S153
SEO GUIDANCE2025-12-10Version CurrentPrimary search-engine guidance

Breadcrumb structured data

Google Search Central

Supports: BreadcrumbList implementation and validation. BreadcrumbList markup guidance BreadcrumbList implementation and validation guidance.

Review status: Periodic review. S154
SEO GUIDANCE2023-08-08Version Current policy context

Changes to HowTo and FAQ rich results

Google Search Central

Supports: FAQ rich results are generally restricted to authoritative government and health sites.

Review status: Periodic review. S155
SEO GUIDANCE2026-07Version CurrentPrimary search-engine guidance

General structured data guidelines

Google Search Central

Supports: JSON-LD recommendation, relevance, accuracy and no guarantee of rich-result display. Accurate visible structured data and no rich-result guarantee

Review status: Durable. S156
SPEC2025-03-26Version 2025-03-26Authoritative specification

Lifecycle 2025-03-26

Model Context Protocol

Supports: Initialization, protocol-version agreement, capability negotiation, initialized notification and session-era lifecycle semantics. Initialization, version and capability negotiation in March 2025 Stateful initialization and negotiated capabilities during the first Streamable HTTP era.

Review status: Live check required. S157
Protocol specification2026-03-12Version 1.0.0; latest released specification rechecked 2026-08-25

Agent2Agent (A2A) Protocol Specification

A2A Project

Supports: The A2A 1.0 specification defines agent discovery, messages, tasks, artifacts, versioning, security, and multiple protocol bindings.

Review status: Durable. S158
SPEC2025-03-26Version 2025-03-26Authoritative specification

Tools

Model Context Protocol

Supports: Tool annotations and March 2025 tool semantics Tool annotations as descriptive hints rather than guarantees

Review status: Durable. S159
SPEC2025-06-18Version 2025-06-18Authoritative specification

Lifecycle

Model Context Protocol

Supports: June 2025 retained initialization and sessions

Review status: Durable. S160
SPEC2025-11-25Version 2025-11-25Authoritative specification

Lifecycle

Model Context Protocol

Supports: Last released initialization/session lifecycle before 2026 stateless core Last released handshake/session-era lifecycle before the 2026 revision.

Review status: Durable. S161
SPEC2025-11-25Version 2025-11-25Authoritative specification

Tools

Model Context Protocol

Supports: November 2025 tool fields and taskSupport execution metadata

Review status: Live check required. S164
DOCS2026-08-25 (retrieved)Version CurrentOfficial project

Extensions Overview

Model Context Protocol

Supports: Extensions are separate from core protocol and version independently

Review status: Live check required. S165
EXTENSION2026-08-25 (retrieved)Version Current extensionOfficial project

MCP Tasks Extension Overview

Model Context Protocol

Supports: Tasks are a separately versioned extension in the 2026 architecture

Review status: Live check required. S166
SDK DOCS2026-08-25 (retrieved)Version SDK v2Official SDK

Protocol Versions

Model Context Protocol Python SDK

Supports: Modern versus handshake-era compatibility model

Review status: Live check required. S167
SDK DOCS2026-08-25 (retrieved)Version SDK v2Official SDK

Client

Model Context Protocol Python SDK

Supports: Local, remote and in-process client options Client connection forms: in-process, Streamable HTTP and stdio; client represents one server relationship.

Review status: Live check required. S168
SDK DOCS2026-08-25 (retrieved)Version SDK v2Official SDK

Supporting protocol revision 2026-07-28

Model Context Protocol TypeScript SDK

Supports: Per-era codecs and current auth migration details SDK implementation notes for discovery, identity and MRTR.

Review status: Live check required. S169
DOCS2026-08-25 (retrieved)Version CurrentPrimary vendor

Function calling

OpenAI

Supports: Current function definitions, tool loop, strict mode, tool choice and tool search

Review status: Live check required. S170
DOCS2026-08-25 (retrieved)Version CurrentPrimary vendor

MCP and Connectors

OpenAI

Supports: Remote MCP listing/calling, approvals and provider-hosted execution

Review status: Live check required. S171
SDK DOCS2026-08-25 (retrieved)Version CurrentOfficial SDK

OpenAI Agents SDK — Tools

OpenAI

Supports: Function tools, hosted MCP tools, tool search, namespaces and execution options

Review status: Live check required. S172
DOCS2026-08-25 (retrieved)Version CurrentPrimary vendor

Structured model outputs

OpenAI

Supports: Distinction between constrained model output and external tool result structure

Review status: Live check required. S173
DOCS2026-08-25 (retrieved)Version CurrentPrimary vendor

Handle tool calls

Anthropic

Supports: Application tool execution and result-return loop

Review status: Live check required. S174
DOCS2026-08-25 (retrieved)Version CurrentPrimary vendor

Tool search tool

Anthropic

Supports: Deferred tool loading and large-catalog search

Review status: Live check required. S175
DOCS2026-08-25 (retrieved)Version CurrentPrimary vendor

MCP connector

Anthropic

Supports: Messages API connection to remote MCP servers The beta Messages API connector uses tools from public HTTPS remote MCP servers over Streamable HTTP or legacy SSE.

Evidence note: First-party product documentation rechecked and normalized on 2026-08-25; the package URL remains in the package source map.

Review status: Periodic review. S176
ENGINEERING2025-11-24Version Current-era analysisPrimary vendor

Advanced tool use

Anthropic

Supports: Tool search and large-catalog context/selection concerns

Review status: Live check required. S177
DOCS2026-07-30 (page update)Version CurrentPrimary vendor

Function calling with the Gemini API

Google

Supports: Gemini function declarations, developer execution, parallel/compositional calls and remote MCP

Review status: Live check required. S178
DOCS2026-08-25 (retrieved)Version CurrentPrimary vendor

Thought signatures

Google

Supports: Provider-specific continuity requirements around tool calls

Review status: Periodic review. S179
STANDARD2026-08-25 (retrieved)Version CurrentPrimary standard organization

What is OpenAPI?

OpenAPI Initiative

Supports: OpenAPI as a machine-readable HTTP API description

Review status: Live check required. S180
STANDARD2026-08-25 (retrieved)Version Current indexPrimary standard organization

OpenAPI Specification

OpenAPI Initiative

Supports: Current OpenAPI versioned specifications

Review status: Durable. S181
STANDARD2020-12Version 2020-12Primary standard

JSON Schema 2020-12

JSON Schema

Supports: Schema dialect used as current MCP default

Review status: Live check required. S183
SERP COMPETITOR2026-04 (published)Version Competitor snapshotSecondary discovery only

MCP vs. Function Calling

Goodcall

Supports: Outdated HTTP+SSE framing in current results

Review status: Live check required. S184
SERP COMPETITOR2025 (published)Version Competitor snapshotSecondary discovery only

MCP vs Function Calling: When to Use Each

AI Agents Kit

Supports: Stateful-MCP comparison still appearing in results

Review status: Live check required. S185
SERP COMPETITOR2026 (retrieved)Version Competitor snapshotSecondary discovery only

MCP vs OpenAI Function Calling

Tetrate

Supports: Persistent-session framing and search-intent coverage

Review status: Durable. S187
SPEC2025-11-25Version 2025-11-25Authoritative specification

Authorization 2025-11-25

Model Context Protocol

Supports: Late-2025 authorization semantics and registration options

Review status: Live check required. S190
FRAMEWORK2026Version v0.1 betaAuthoritative project source

OWASP MCP Top 10

OWASP Foundation

Supports: Community risk taxonomy; beta rather than final standard

Review status: Durable. S193
STANDARD2012-10Version RFC 6750Formal standards source

OAuth 2.0 Bearer Token Usage

IETF

Supports: Bearer-token transmission and challenge rules

Review status: Live check required. S205
SECURITY ADVISORY2025-07-04Version <1.9.4Vendor advisory / CVE

CVE-2025-53366: Validation error amplification / denial of service

MCP Python SDK

Supports: Validation error amplification / denial of service; patched/fixed status: 1.9.4

Evidence note: Layer: SDK. Verify current affected and fixed ranges before publication.

Review status: Live check required. S206
SECURITY ADVISORY2025-07-04Version <1.10.0Vendor advisory / CVE

CVE-2025-53365: Closed-resource handling denial of service

MCP Python SDK

Supports: Closed-resource handling denial of service; patched/fixed status: 1.10.0

Evidence note: Layer: SDK. Verify current affected and fixed ranges before publication.

Review status: Live check required. S207
SECURITY ADVISORY2026-02-20Version <1.4.0Vendor advisory / CVE

CVE-2026-34742: DNS rebinding protection gap for localhost HTTP servers

MCP Go SDK

Supports: DNS rebinding protection gap for localhost HTTP servers; patched/fixed status: 1.4.0

Evidence note: Layer: SDK/transport. Verify current affected and fixed ranges before publication.

Review status: Live check required. S208
SECURITY ADVISORY2026-02-26Version <1.0.0Vendor advisory / CVE

CVE-2026-35568: DNS rebinding protection gap for localhost HTTP servers

MCP Java SDK

Supports: DNS rebinding protection gap for localhost HTTP servers; patched/fixed status: 1.0.0

Evidence note: Layer: SDK/transport. Verify current affected and fixed ranges before publication.

Review status: Live check required. S209
SECURITY ADVISORY2026-04-14Version <1.4.0Vendor advisory / CVE

CVE-2026-42559: DNS rebinding protection gap

MCP Rust SDK

Supports: DNS rebinding protection gap; patched/fixed status: 1.4.0

Evidence note: Layer: SDK/transport. Verify current affected and fixed ranges before publication.

Review status: Live check required. S210
SECURITY ADVISORY2026-06-08Version <=0.22.0Vendor advisory / CVE

CVE-2026-63118: DNS rebinding protection gap

MCP Ruby SDK

Supports: DNS rebinding protection gap; patched/fixed status: 0.23.0

Evidence note: Layer: SDK/transport. Verify current affected and fixed ranges before publication.

Review status: Live check required. S212
SECURITY ADVISORY2026-06-24Version LIVE-CHECK REQUIREDVendor advisory / CVE

CVE-2026-67430: Unbounded stdio message handling can exhaust resources

MCP Ruby SDK

Supports: Unbounded stdio message handling can exhaust resources; patched/fixed status: 0.23.0 reported

Evidence note: Layer: SDK/stdio. Verify current affected and fixed ranges before publication.

Review status: Live check required. S213
SECURITY ADVISORY2026-06-24Version LIVE-CHECK REQUIREDVendor advisory / CVE

CVE-2026-67432: Legacy session retention / cleanup flaw

MCP Ruby SDK

Supports: Legacy session retention / cleanup flaw; patched/fixed status: 0.23.0 reported

Evidence note: Layer: SDK/session. Verify current affected and fixed ranges before publication.

Review status: Live check required. S214
SECURITY ADVISORY2026-01-08Version <1.25.2Vendor advisory / CVE

CVE-2026-0621: UriTemplate regular-expression denial of service

MCP TypeScript SDK

Supports: UriTemplate regular-expression denial of service; patched/fixed status: 1.25.2

Evidence note: Layer: SDK/parser. Verify current affected and fixed ranges before publication.

Review status: Live check required. S215
SECURITY ADVISORY2025-10-16Version <2025.9.25Vendor advisory / CVE

CVE-2025-68143: Repository path validation weakness

MCP reference Git server

Supports: Repository path validation weakness; patched/fixed status: 2025.9.25 / server removed

Evidence note: Layer: Server implementation. Verify current affected and fixed ranges before publication.

Review status: Live check required. S216
SECURITY ADVISORY2026-04-29Version <1.7.7Vendor advisory / CVE

CVE-2026-44430: Server-side request forgery in registry processing

Official MCP Registry

Supports: Server-side request forgery in registry processing; patched/fixed status: 1.7.7

Evidence note: Layer: Registry. Verify current affected and fixed ranges before publication.

Review status: Live check required. S217
SECURITY ADVISORY2026-04-29Version <1.7.6Vendor advisory / CVE

CVE-2026-44428: OIDC token replay / validation flaw

Official MCP Registry

Supports: OIDC token replay / validation flaw; patched/fixed status: 1.7.6

Evidence note: Layer: Registry/auth. Verify current affected and fixed ranges before publication.

Review status: Live check required. S218
SECURITY ADVISORY2026-04-29Version >=1.1.0,<1.7.5Vendor advisory / CVE

CVE-2026-44427: Open redirect

Official MCP Registry

Supports: Open redirect; patched/fixed status: 1.7.5

Evidence note: Layer: Registry/web. Verify current affected and fixed ranges before publication.

Review status: Live check required. S219
SECURITY ADVISORY2026-05-01Version LIVE-CHECK REQUIREDVendor advisory / CVE

GHSA-rqv2-m695-f8j4: Stored cross-site scripting

Official MCP Registry

Supports: Stored cross-site scripting; patched/fixed status: LIVE-CHECK REQUIRED

Evidence note: Layer: Registry/web. Verify current affected and fixed ranges before publication.

Review status: Live check required. S220
SECURITY ADVISORY2026-05-01Version <1.7.9Vendor advisory / CVE

GHSA-2v5f-5r6w-p67r: OCI verification fail-open behavior

Official MCP Registry

Supports: OCI verification fail-open behavior; patched/fixed status: 1.7.9

Evidence note: Layer: Registry/supply chain. Verify current affected and fixed ranges before publication.

Review status: Live check required. S221
SECURITY ADVISORY2025-08-29Version <0.0.40Vendor advisory / CVE

CVE-2025-9611: DNS rebinding against localhost HTTP mode

Microsoft Playwright MCP

Supports: DNS rebinding against localhost HTTP mode; patched/fixed status: 0.0.40

Evidence note: Layer: Server/transport. Verify current affected and fixed ranges before publication.

Review status: Live check required. S222
SECURITY ADVISORY2026-08-07Version <1.2.0Vendor advisory / CVE

CVE-2026-9739: DNS rebinding in legacy SSE/local deployment

Google MCP Toolbox for Databases

Supports: DNS rebinding in legacy SSE/local deployment; patched/fixed status: 1.2.0

Evidence note: Layer: Server/transport. Verify current affected and fixed ranges before publication.

Review status: Live check required. S223
SECURITY ADVISORY2026-03-03Version <0.17.0Vendor advisory / CVE

GHSA-jwj7-74jh-p5c4: DNS rebinding protection weakness

CircleCI MCP Server

Supports: DNS rebinding protection weakness; patched/fixed status: 0.17.0

Evidence note: Layer: Server/transport. Verify current affected and fixed ranges before publication.

Review status: Live check required. S224
SECURITY ADVISORY2026-01-16Version <=1.4.2Vendor advisory / CVE

CVE-2026-23744: Remote command execution

MCPJam Inspector

Supports: Remote command execution; patched/fixed status: 1.4.3

Evidence note: Layer: Host/developer tool. Verify current affected and fixed ranges before publication.

Review status: Live check required. S226
SECURITY ADVISORY2026-05-20Version <=3.0.1Vendor advisory / CVE

CVE-2026-49257: Network service bound broadly without authentication

mcp-pinot

Supports: Network service bound broadly without authentication; patched/fixed status: 3.1.0

Evidence note: Layer: Server/deployment. Verify current affected and fixed ranges before publication.

Review status: Live check required. S227
SECURITY ADVISORY2026-04-20Version <1.1.0Vendor advisory / CVE

CVE-2026-47427: Nil-pointer denial of service

GitHub MCP Server

Supports: Nil-pointer denial of service; patched/fixed status: 1.1.0

Evidence note: Layer: Server implementation. Verify current affected and fixed ranges before publication.

Review status: Live check required. S228
SECURITY ADVISORY2026-05-16Version >=0.22.0,<1.1.2Vendor advisory / CVE

CVE-2026-48529: Lockdown mode cross-user authorization separation flaw

GitHub MCP Server

Supports: Lockdown mode cross-user authorization separation flaw; patched/fixed status: 1.1.2

Evidence note: Layer: Server/authorization. Verify current affected and fixed ranges before publication.

Review status: Live check required. S230
SECURITY ADVISORY2026-05-29Version >=2.26.2,<2.26.4Vendor advisory / CVE

CVE-2026-55786: Unauthenticated command execution through MCP capability

flyto-core

Supports: Unauthenticated command execution through MCP capability; patched/fixed status: 2.26.4

Evidence note: Layer: Server implementation. Verify current affected and fixed ranges before publication.

Review status: Live check required. S231
SECURITY ADVISORY2026-01-15Version <0.3.0Vendor advisory / CVE

CVE-2026-11529: SQL injection through insufficient input handling

MySQL MCP Server

Supports: SQL injection through insufficient input handling; patched/fixed status: 0.3.0

Evidence note: Layer: Server implementation. Verify current affected and fixed ranges before publication.

Review status: Live check required. S232
SECURITY ADVISORY2026-05-22Version <=1.7.0Vendor advisory / CVE

CVE-2026-5059: Command injection

aws-mcp

Supports: Command injection; patched/fixed status: No patch listed when recorded

Evidence note: Layer: Server implementation. Verify current affected and fixed ranges before publication.

Review status: Live check required. S234
SECURITY ADVISORY2026-05-25Version <0.10.11Vendor advisory / CVE

CVE-2026-50143: Path/token authorization weakness

Apify MCP Server

Supports: Path/token authorization weakness; patched/fixed status: 0.10.11

Evidence note: Layer: Server/authorization. Verify current affected and fixed ranges before publication.

Review status: Live check required. S235
SECURITY ADVISORY2026-03-24Version LIVE-CHECK REQUIREDVendor advisory / CVE

CVE-2026-31944: OAuth callback binding/account-linking weakness

LibreChat

Supports: OAuth callback binding/account-linking weakness; patched/fixed status: 0.8.3-rc1 reported

Evidence note: Layer: Host/auth. Verify current affected and fixed ranges before publication.

Review status: Live check required. S236
SECURITY ADVISORY2026-03-26Version <=0.8.3Vendor advisory / CVE

CVE-2026-32625: Environment-expanded MCP URL can expose secrets

LibreChat

Supports: Environment-expanded MCP URL can expose secrets; patched/fixed status: 0.8.4-rc1 reported

Evidence note: Layer: Host/configuration. Verify current affected and fixed ranges before publication.

Review status: Live check required. S237
SECURITY ADVISORY2026-03-26Version >=0.8.2-rc1,<=0.8.3-rc1Vendor advisory / CVE

GHSA-pmw7-gqwj-f954: Attacker-controlled headers can expose tokens

LibreChat

Supports: Attacker-controlled headers can expose tokens; patched/fixed status: >=0.8.3-rc2

Evidence note: Layer: Host/auth. Verify current affected and fixed ranges before publication.

Review status: Live check required. S238
SECURITY ADVISORY2026-04-01Version <4.5.128Vendor advisory / CVE

CVE-2026-40159: Environment variables inherited by local MCP processes

PraisonAI

Supports: Environment variables inherited by local MCP processes; patched/fixed status: 4.5.128

Evidence note: Layer: Host/local process. Verify current affected and fixed ranges before publication.

Review status: Live check required. S239
SECURITY ADVISORY2026-04-10Version <=4.5.148Vendor advisory / CVE

CVE-2026-41497: Unsafe command parsing for MCP server configuration

PraisonAI

Supports: Unsafe command parsing for MCP server configuration; patched/fixed status: Patched after 4.5.148

Evidence note: Layer: Host/local process. Verify current affected and fixed ranges before publication.

Review status: Live check required. S240
SECURITY ADVISORY2026-06-01Version <=4.6.48Vendor advisory / CVE

CVE-2026-57124: Unauthenticated remote MCP connect path

PraisonAI

Supports: Unauthenticated remote MCP connect path; patched/fixed status: 4.6.59

Evidence note: Layer: Host/network. Verify current affected and fixed ranges before publication.

Review status: Live check required. S241
SECURITY ADVISORY2026-05-12Version <=4.6.39Vendor advisory / CVE

CVE-2026-47394: Arbitrary local file read through MCP integration

PraisonAI

Supports: Arbitrary local file read through MCP integration; patched/fixed status: 4.6.40

Evidence note: Layer: Host/server. Verify current affected and fixed ranges before publication.

Review status: Live check required. S242
SECURITY ADVISORY2026-03-15Version <=2.3.3 reportedVendor advisory / CVE

CVE-2026-33032: Unauthenticated MCP endpoint enabling administrative takeover

Nginx UI MCP integration

Supports: Unauthenticated MCP endpoint enabling administrative takeover; patched/fixed status: 2.3.4 reported

Evidence note: Layer: Server/product integration. Verify current affected and fixed ranges before publication.

Review status: Live check required. S243
SECURITY ADVISORY2025-07-09Version LIVE-CHECK REQUIREDVendor advisory / CVE

CVE-2025-6514: Command injection in remote-server launcher

mcp-remote

Supports: Command injection in remote-server launcher; patched/fixed status: LIVE-CHECK REQUIRED

Evidence note: Layer: Launcher/supply chain. Verify current affected and fixed ranges before publication.

Review status: Live check required. S244
SECURITY ADVISORY2026-01-23Version >=1.0.16 malicious seriesVendor advisory / CVE

MALICIOUS-PACKAGE: Malicious npm package impersonating an official server and exfiltrating API keys

Postmark MCP impersonator

Supports: Malicious npm package impersonating an official server and exfiltrating API keys; patched/fixed status: Remove package; use verified vendor source

Evidence note: Layer: Supply chain. Verify current affected and fixed ranges before publication.

Review status: Live check required. S245
SECURITY ADVISORY2025-09-17Version Before 2025.09.17-25b418fVendor advisory / CVE

CVE-2025-64109: Malicious project MCP configuration can trigger code execution

Cursor

Supports: Malicious project MCP configuration can trigger code execution; patched/fixed status: 2025.09.17-25b418f

Evidence note: Layer: Host/project config. Verify current affected and fixed ranges before publication.

Review status: Live check required. S247
SECURITY ADVISORY2026-04-22Version <=2026.4.21Vendor advisory / CVE

CVE-2026-44118: Owner identity spoofing in MCP-connected workflow

OpenClaw

Supports: Owner identity spoofing in MCP-connected workflow; patched/fixed status: 2026.4.22

Evidence note: Layer: Host/identity. Verify current affected and fixed ranges before publication.

Review status: Live check required. S248
SECURITY POLICY2026Version CurrentOfficial repository

Project Security Policy

Model Context Protocol

Supports: Vulnerability reporting and scope

Review status: Durable. S249
SPEC2024-11-05Version 2024-11-05Primary or first-party source

Specification Overview — MCP 2024-11-05

Model Context Protocol

Supports: Launch-era host, client and server roles and stateful capability-negotiated architecture.

Evidence note: Normalized from the checksum-verified research/5 architecture package.

Review status: Durable. S250
SPEC2024-11-05Version 2024-11-05Primary or first-party source

Base Protocol — MCP 2024-11-05

Model Context Protocol

Supports: Launch-era protocol layering and absence of the later core authorization framework.

Evidence note: Normalized from the checksum-verified research/5 architecture package.

Review status: Durable. S251
SPEC2025-06-18Version 2025-06-18Primary or first-party source

Architecture — MCP 2025-06-18

Model Context Protocol

Supports: Legacy architecture: host manages clients; each client maintains a stateful session with one server; isolation principles.

Evidence note: Normalized from the checksum-verified research/5 architecture package.

Review status: Live check required. S252
SDK DOC2026-07-28Version 2026-07-28Primary or first-party source

TypeScript SDK v2 Documentation

Model Context Protocol

Supports: Official TypeScript SDK v2 support for current MCP and examples of hosts connecting to servers.

Evidence note: Normalized from the checksum-verified research/5 architecture package.

Review status: Live check required. S253
SDK DOC2026-07-28Version 2026-07-28Primary or first-party source

TypeScript SDK Protocol Versions

Model Context Protocol

Supports: Modern versus legacy protocol eras and automatic compatibility behavior.

Evidence note: Normalized from the checksum-verified research/5 architecture package.

Review status: Live check required. S254
SDK DOC2026-07-28Version 2026-07-28Primary or first-party source

Ruby SDK Client Lifecycle

Model Context Protocol

Supports: Official SDK handling of both legacy and current protocol eras.

Evidence note: Normalized from the checksum-verified research/5 architecture package.

Review status: Live check required. S255
SDK DOC2026-07-28Version 2026-07-28Primary or first-party source

PHP SDK Client Connections

Model Context Protocol

Supports: Current connection behavior without an initialization handshake.

Evidence note: Normalized from the checksum-verified research/5 architecture package.

Review status: Live check required. S256
SDK DOC2026-07-28Version CurrentPrimary or first-party source

Java SDK Client Documentation

Model Context Protocol

Supports: Official Java client implementation responsibilities and transports.

Evidence note: Normalized from the checksum-verified research/5 architecture package.

Review status: Live check required. S257
SDK DOC2026-07-28Version CurrentPrimary or first-party source

Java SDK Server Documentation

Model Context Protocol

Supports: Official Java server implementation responsibilities and capabilities.

Evidence note: Normalized from the checksum-verified research/5 architecture package.

Review status: Live check required. S258
VENDOR DOC2026-08-25Version Current product statePrimary or first-party source

When to use desktop and web connectors

Anthropic

Supports: Anthropic distinguishes local desktop extensions from cloud-brokered remote connectors across supported Claude surfaces.

Evidence note: Normalized from the checksum-verified research/5 architecture package; first-party product documentation rechecked and corrected on 2026-08-25.

Review status: Live check required. S259
VENDOR DOC2026-08-25Version Current product statePrimary or first-party source

Connect Claude Code to tools via MCP

Anthropic

Supports: Claude Code as an MCP host/client and optional MCP server through claude mcp serve.

Evidence note: Normalized from the checksum-verified research/5 architecture package; first-party product documentation rechecked and corrected on 2026-08-25.

Review status: Live check required. S260
VENDOR DOC2026-06-30Version Current product statePrimary or first-party source

Getting started with local MCP servers on Claude Desktop

Anthropic

Supports: Claude Desktop local server configuration and management.

Evidence note: Normalized from the checksum-verified research/5 architecture package; first-party product documentation rechecked and corrected on 2026-08-25.

Review status: Live check required. S261
DOCS2026-08-25Version Live documentation checked 2026-08-25Primary or first-party source

Secure MCP Tunnel

OpenAI

Supports: Supported private, on-premises, and developer-machine MCP servers can be exposed to ChatGPT through Secure MCP Tunnel.

Evidence note: Added during the 2026-08-25 first-party product-source review; not part of the byte-exact research/5 archive.

Review status: Live check required. S262
VENDOR RELEASE2025-06-04Version Historical adoptionPrimary or first-party source

ChatGPT — Release Notes

OpenAI

Supports: Initial ChatGPT custom connector support through remote MCP.

Evidence note: Normalized from the checksum-verified research/5 architecture package; first-party product documentation rechecked and corrected on 2026-08-25.

Review status: Live check required. S263
VENDOR RELEASE2025-03-01Version Historical adoptionPrimary or first-party source

Visual Studio Code 1.99 Release Notes

Microsoft

Supports: Initial VS Code MCP support in agent mode.

Evidence note: Normalized from the checksum-verified research/5 architecture package.

Review status: Live check required. S264
VENDOR BLOG2026-05-15Version Current architecture contextPrimary or first-party source

The Coding Harness Behind GitHub Copilot in VS Code

Microsoft

Supports: Agent harness responsibilities: context, model loop, tool calls and execution coordination.

Evidence note: Normalized from the checksum-verified research/5 architecture package; first-party product documentation rechecked and corrected on 2026-08-25.

Review status: Live check required. S265
VENDOR DOC2026-08-25Version Current product statePrimary or first-party source

Extending GitHub Copilot cloud agent with MCP

GitHub

Supports: GitHub Copilot cloud agent can use tools from configured MCP servers, subject to its documented capability, authentication, and approval limitations.

Evidence note: Normalized from the checksum-verified research/5 architecture package; first-party product documentation rechecked and corrected on 2026-08-25.

Review status: Live check required. S266
VENDOR DOC2026-08-25Version Current product statePrimary or first-party source

Configuring MCP servers for GitHub Copilot cloud agent

GitHub

Supports: GitHub documents how to configure MCP servers for GitHub Copilot cloud agent.

Evidence note: Normalized from the checksum-verified research/5 architecture package; first-party product documentation rechecked and corrected on 2026-08-25.

Review status: Live check required. S267
VENDOR DOC2026-08-25Version Current product statePrimary or first-party source

Use the GitHub MCP Server from Copilot Chat

GitHub

Supports: Copilot Chat host/client behavior with a preconfigured GitHub MCP server and user approval.

Evidence note: Normalized from the checksum-verified research/5 architecture package.

Review status: Live check required. S268
VENDOR DOC2026-08-25Version Current product statePrimary or first-party source

Adding MCP servers for GitHub Copilot CLI

GitHub

Supports: Copilot CLI local and remote MCP server support.

Evidence note: Normalized from the checksum-verified research/5 architecture package; first-party product documentation rechecked and corrected on 2026-08-25.

Review status: Live check required. S269
VENDOR DOC2026-08-25Version Current product statePrimary or first-party source

Model Context Protocol (MCP)

Cursor

Supports: Cursor as a host/client connecting to external MCP tools and data.

Evidence note: Normalized from the checksum-verified research/5 architecture package; first-party product documentation rechecked and corrected on 2026-08-25.

Review status: Live check required. S270
DOCS2026-08-25Version Live documentation checked 2026-08-25Primary or first-party source

Agent Host

Microsoft

Supports: Microsoft Agent Host is a distinct AHP runtime or process and should not be confused with the MCP host role.

Evidence note: Added during the 2026-08-25 first-party product-source review; not part of the byte-exact research/5 archive.

Review status: Live check required. S271
VENDOR DOC2026-08-25Version Current product statePrimary or first-party source

Getting Started with Google MCP Servers

Google

Supports: Gemini CLI registration and use of Google-hosted MCP servers.

Evidence note: Normalized from the checksum-verified research/5 architecture package.

Review status: Live check required. S272
VENDOR BLOG2025-12-17Version Current product/security statePrimary or first-party source

Zed Moves Toward Secure-by-Default: Introducing Worktree Trust

Zed Industries

Supports: Zed host behavior around project trust and automatic MCP server execution.

Evidence note: Normalized from the checksum-verified research/5 architecture package.

Review status: Live check required. S273
VENDOR DOC2026-08-25Version Current product statePrimary or first-party source

Tool Permissions in Zed

Zed Industries

Supports: Host-level MCP tool allow, deny and confirm policy.

Evidence note: Normalized from the checksum-verified research/5 architecture package.

Review status: Live check required. S274
VENDOR DOC2026-08-14Version AI Assistant 2026.2Primary or first-party source

Model Context Protocol in JetBrains AI Assistant

JetBrains

Supports: JetBrains AI Assistant as MCP host/client; stdio, Streamable HTTP and legacy SSE support.

Evidence note: Normalized from the checksum-verified research/5 architecture package; first-party product documentation rechecked and corrected on 2026-08-25.

Review status: Live check required. S275
VENDOR DOC2026-05-13Version PyCharm 2026.2Primary or first-party source

MCP Server

JetBrains

Supports: JetBrains IDEs as MCP servers exposing IDE tools to external clients.

Evidence note: Normalized from the checksum-verified research/5 architecture package; first-party product documentation rechecked and corrected on 2026-08-25.

Review status: Live check required. S276
VENDOR KB2026-02-01Version Current product statePrimary or first-party source

How JetBrains MCP Client and Server Options Differ

JetBrains

Supports: Explicit distinction between JetBrains AI Assistant as client and the IDE as server.

Evidence note: Normalized from the checksum-verified research/5 architecture package.

Review status: Live check required. S277
VENDOR DOC2026-08-03Version AI Assistant 2026.2Primary or first-party source

Agents

JetBrains

Supports: JetBrains host can pass configured MCP tools to several agent implementations.

Evidence note: Normalized from the checksum-verified research/5 architecture package; first-party product documentation rechecked and corrected on 2026-08-25.

Review status: Periodic review. S278
COMPETITOR2026-08-25Version Search-result auditSecondary source

MCP Server vs Client

Tricentis

Supports: Competitor page retaining initialize-based legacy architecture; used only for SERP gap analysis.

Evidence note: Normalized from the checksum-verified research/5 architecture package.

Review status: Periodic review. S279
COMPETITOR2026-08-25Version Search-result auditSecondary source

MCP Architecture

Stanza

Supports: Competitor page retaining initialization-centered architecture; used only for SERP gap analysis.

Evidence note: Normalized from the checksum-verified research/5 architecture package.

Review status: Periodic review. S280
COMPETITOR2026-08-25Version Search-result auditSecondary source

MCP Glossary

MCP Server Spot

Supports: Competitor glossary using legacy session terminology; used only for SERP gap analysis.

Evidence note: Normalized from the checksum-verified research/5 architecture package.

Review status: Live check required. S281
SEO GUIDANCE2025-12-10Version Current guidancePrimary or first-party source

SEO Guide for Web Developers

Google Search Central

Supports: Unique title/meta, semantic HTML and DOM-accessible content.

Evidence note: Normalized from the checksum-verified research/5 architecture package.

Review status: Live check required. S282
SEO GUIDANCE2025-12-10Version Current guidancePrimary or first-party source

Ask Google to Recrawl Your URLs

Google Search Central

Supports: URL Inspection, sitemap submission and no guarantee of immediate indexing.

Evidence note: Normalized from the checksum-verified research/5 architecture package.

Review status: Live check required. S283
DOCS2026-08-25Version Live documentation checked 2026-08-25Primary or first-party source

Model Context Protocol in Cursor CLI

Cursor

Supports: Cursor CLI is a distinct MCP-consuming surface that shares MCP configuration with the Cursor editor.

Evidence note: Added during the 2026-08-25 first-party product-source review; not part of the byte-exact research/5 archive.

Review status: Live check required. S284
DOCS2026-08-25Version Live documentation checked 2026-08-25Primary or first-party source

Model Context Protocol in Zed

Zed Industries

Supports: Zed documents current MCP server configuration and its host-side MCP integration.

Evidence note: Added during the 2026-08-25 first-party product-source review; not part of the byte-exact research/5 archive.

Review status: Live check required. S285
DOCS2026-08-25Version Live documentation checked 2026-08-25Primary or first-party source

Worktree Trust

Zed Industries

Supports: Restricted Mode blocks project-configured language and MCP servers until trust; globally configured servers are outside that gate.

Evidence note: Added during the 2026-08-25 first-party product-source review; not part of the byte-exact research/5 archive.