GHSA-vj7q-gjh5-988w: MCP Python SDK: WebSocket server transport does not support Host/Origin validation
- Identifiers
- CVE-2026-59950GHSA-vj7q-gjh5-988w
- Published
- Record updated
- Affected
- mcp < 1.28.1
- Fixed in
- 1.28.1
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.2%
Summary
The deprecated WebSocket server transport, mcp.server.websocket.websocket_server, in the MCP Python SDK accepted WebSocket handshakes without validating the Host or Origin headers, because TransportSecuritySettings was never wired into it. A malicious web page can open a connection to an exposed server on this transport, complete initialize, and invoke its tools and read its resources, and the transport requires no token or prior session. Only applications that wire this transport into their own ASGI server are affected.
Mitigation
Upgrade to version 1.28.1 or later, which adds the optional security_settings: TransportSecuritySettings argument and validates Host and Origin headers, rejecting failed requests with HTTP 403 and ValueError("Request validation failed"). The parameter defaults to None, which leaves validation disabled, so pass a TransportSecuritySettings with enable_dns_rebinding_protection=True and appropriate allowed_hosts / allowed_origins. The recommended path is to migrate to Streamable HTTP, where FastMCP enables this protection automatically for localhost binds. The WebSocket transport has been removed entirely in v2.
Topics
Related items
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpointsSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- CriticalHermes Agent - PKCE Session Takeover via Redirect-URI Parser ConfusionSimilar attack · Tenable Research Advisories
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database