HIGH🇵🇱 Wersja polska

CVE-2026-52869

CVSS 7.1v3.1pub. 2026-07-15upd. 2026-07-17

The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2, the SSE and stateful Streamable HTTP transports mcp.server.sse.SseServerTransport and mcp.server.streamable_http_manager.StreamableHTTPSessionManager route requests to existing sessions using only the session_id query parameter or Mcp-Session-Id header without verifying the authenticated principal that created the session, allowing a different bearer-token-authenticated client with a known session ID to inject JSON-RPC messages into that session. This issue is fixed in version 1.27.2.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
  • Lfprojects Mcp Python Sdk

    APP
    Lfprojects
    < 1.27.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-52870HIGH7.6PL ✓same product

MCP Python SDK: brak kontroli dostępu do zadań między sesjami klientów

CVE-2026-59950HIGH7.6PL ✓same product

Brak walidacji nagłówków Origin/Host w MCP Python SDK (WebSocket)

CVE-2025-66416HIGH7.6same product

The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prio...

CVE-2026-64849CRITICAL9.3⚠ KEVsame vendor

MLflow is an open source AI engineering platform for agents, large language models, and machine learning model...

CVE-2026-2651CRITICAL9.0PL ✓same vendor

MLflow: nieautoryzowany dostęp do endpointów multipart upload (RCE)