Skip to content
HighVulnerability

GHSA-hvrp-rf83-w775: MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks

Published
Record updated
View JSON
Affected
  • mcp >= 1.23.0, <= 1.27.1
Fixed in
1.27.2
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.4%

Summary

The MCP Python SDK's experimental task handlers, enabled through `server.experimental.enable_tasks()`, did not check which session created a task before acting on it. On a multi-client server, any connected client could list, read, cancel, and consume queued messages such as elicitation requests belonging to other clients' tasks.

Mitigation

Upgrade to version 1.27.2 or later, in which task IDs generated by `run_task()` embed an opaque per-session marker and the default handlers restrict each session to its own tasks. Alternatively, leave the experimental tasks feature disabled, or register task handlers that validate session ownership.