HighVulnerability
GHSA-hvrp-rf83-w775: MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks
- Identifiers
- CVE-2026-52870GHSA-hvrp-rf83-w775
- Published
- Record updated
- Affected
- mcp >= 1.23.0, <= 1.27.1
- Fixed in
- 1.27.2
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.4%
Summary
The MCP Python SDK's experimental task handlers, enabled through `server.experimental.enable_tasks()`, did not check which session created a task before acting on it. On a multi-client server, any connected client could list, read, cancel, and consume queued messages such as elicitation requests belonging to other clients' tasks.
Mitigation
Upgrade to version 1.27.2 or later, in which task IDs generated by `run_task()` embed an opaque per-session marker and the default handlers restrict each session to its own tasks. Alternatively, leave the experimental tasks feature disabled, or register task handlers that validate session ownership.
Topics
Related items
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpointsSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- CriticalHermes Agent - PKCE Session Takeover via Redirect-URI Parser ConfusionSimilar attack · Tenable Research Advisories
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database