modelcontextprotocol · Issues· 153 open
Open on GitHubLocally synced open issues (discussions stay on GitHub)
- #3373
doc typo, "Serves" should be "Servers" in draft resources spec
bugUpdated Sep 19, 2026 - #3370
Origin validation rejects browser-based MCP clients on authenticated remote servers
bugUpdated Sep 19, 2026 - #3354
SEP Extension proposal: verifiable tool results(Verifiable MCP) — ZK proofs / TEE attestations attached to `tools/call` results (working reference implementation, pre-SEP feedback)
trackingUpdated Sep 18, 2026 - #540
Discussion: Should an MCP Server Expose Its Resource List Before Authentication?
authsecurityUpdated Sep 18, 2026 - #3369
Two JSON example code blocks in the docs do not parse (2025-06-18 tools page, SEP-1330)
Updated Sep 18, 2026 - #229
Pagination for tool/call
enhancementUpdated Sep 16, 2026 - #1488
SEP-1488: securitySchemes in Tool Metadata for Mixed-Auth Servers
authsecuritySEPdraftUpdated Sep 15, 2026 - #3361
Security considerations section can be improved
bugUpdated Sep 14, 2026 - #292
Define a Standard MCP Configuration Schema
enhancementUpdated Sep 14, 2026 - #3347
Custom OAuth MCP connector: intermittent 'Couldn't connect'/'Couldn't reach' errors despite server-side OAuth + protocol succeeding every time
bugUpdated Sep 13, 2026 - #3357
docs: Fix double border in the footer
bugUpdated Sep 12, 2026 - #3350
SEP submission: Tool Outcome Attestation extension (dev.agentstatus/toa)
Updated Sep 12, 2026 - #3213
MCP-2026-015: server/discover instructions field enables prompt injection (amplified by cacheScope:public)
Updated Sep 10, 2026 - #3345
Authorization flow documentation still talks about DCR (deprecated) and does not mention CIMD
bugUpdated Sep 9, 2026 - #3207
MCP-2026-008: CacheableResult cacheScope:public enables cross-user cache poisoning
Updated Sep 7, 2026