GHSA-jpw9-pfvf-9f58: MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal
- Identifiers
- CVE-2026-52869GHSA-jpw9-pfvf-9f58
- Published
- Record updated
- Affected
- mcp <= 1.27.1
- Fixed in
- 1.27.2
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.5%
Summary
Affected versions of the MCP Python SDK route requests on the SSE and Streamable HTTP transports to an existing session using only the session identifier, without checking that the request carries the same authenticated principal that created the session. Anyone who learns or guesses a session ID, such as the `session_id` query parameter or `Mcp-Session-Id` header, can send JSON-RPC messages into that session regardless of their bearer token. Only servers that use an HTTP transport and built-in bearer-token authentication are affected; stdio, stateless Streamable HTTP, and unauthenticated servers are not.
Mitigation
Upgrade to version 1.27.2 or later, which records the authenticated principal that created each session and returns a 404 to requests presenting a different principal. Deployments where many end users share one OAuth client should ensure the token verifier populates `AccessToken.subject`, for example from the `sub` claim, so sessions are isolated per user. Deployments using a custom authentication backend other than `BearerAuthBackend` should enforce an equivalent check themselves.
Topics
Related items
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpointsSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- CriticalHermes Agent - PKCE Session Takeover via Redirect-URI Parser ConfusionSimilar attack · Tenable Research Advisories
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database