{"data":{"id":"493c0843-a7e2-44f3-9f98-6d5a6c3e2b4a","title":"GHSA-jpw9-pfvf-9f58: MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal","summary":"Affected versions of the MCP Python SDK route requests on the SSE and Streamable HTTP transports to an existing session using only the session identifier, without checking that the request carries the same authenticated principal that created the session. Anyone who learns or guesses a session ID, such as the `session_id` query parameter or `Mcp-Session-Id` header, can send JSON-RPC messages into that session regardless of their bearer token. Only servers that use an HTTP transport and built-in bearer-token authentication are affected; stdio, stateless Streamable HTTP, and unauthenticated servers are not.","solution":"Upgrade to version 1.27.2 or later, which records the authenticated principal that created each session and returns a 404 to requests presenting a different principal. Deployments where many end users share one OAuth client should ensure the token verifier populates `AccessToken.subject`, for example from the `sub` claim, so sessions are isolated per user. Deployments using a custom authentication backend other than `BearerAuthBackend` should enforce an equivalent check themselves.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-jpw9-pfvf-9f58","publishedAt":"2026-07-16T19:58:53.000Z","cveId":"CVE-2026-52869","cweIds":["CWE-639"],"cvssScore":"7.1","cvssSeverity":"high","severity":"high","attackType":["other"],"issueType":"vulnerability","affectedPackages":["mcp@<= 1.27.1 (fixed: 1.27.2)"],"affectedPackageNames":["mcp"],"affectedVendors":[],"affectedVendorsRaw":["MCP Python SDK","Model Context Protocol"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L","attackVector":"network","attackComplexity":"high","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00535,"epssCheckedAt":"2026-10-10T04:57:25.196Z","kevDateAdded":null,"advisoryAliases":["GHSA-jpw9-pfvf-9f58"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2026-07-16T19:58:53.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}