The MCP Connector version 1.0.0, which was officially released on July 10, 2025, has raised a question regarding its underlying specification compliance. Specifically, there is uncertainty about which version of the Model Context Protocol (MCP) specification this connector implements. The possible specifications under consideration are:
MCP Spec version 2025-06-18
MCP Spec version 2025-03-26
MCP Spec version 2024-11-05
This query is particularly important in light of a critical remote code execution vulnerability that was publicly disclosed on July 10, 2025, affecting earlier implementations of the MCP protocol. According to the report published by The Hacker News (link), this vulnerability impacts MCP servers and clients that do not fully comply with the latest security measures introduced in the June 18, 2025 spec update.
Given the timing of the connector's release, there is a need to confirm whether MCP Connector v1.0.0 adheres to the latest specification (2025-06-18), which includes the necessary security enhancements to mitigate this vulnerability.
For reference, the official MCP specification for June 18, 2025 can be reviewed here:
https://modelcontextprotocol.io/specification/2025-06-18/server/resources
Additionally, the current MuleSoft documentation for the MCP Connector is available at:
https://docs.mulesoft.com/mcp-connector/latest/
It is crucial to validate which MCP specification version MCP Connector 1.0.0 is built against in order to assess the risk and determine if an upgrade or patch is necessary to address the vulnerability.
The MCP Connector version 1.0.0 is built using version 0.10.0 of the MCP Java SDK, as outlined in the official documentation:
https://modelcontextprotocol.io/sdk/java/mcp-overview
It is important to note that the recently disclosed vulnerability is specific to the mcp-remote module. This particular module is not included as a dependency in the implementation of the MCP Connector's client-side functionality. As such, MCP Connector 1.0.0 is not impacted by the reported issue.
005131262

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.