PT-2026-53225 · Pypi · Mcp Python Sdk

CVE-2026-52869

·

Published

2026-06-27

·

Updated

2026-07-27

CVSS v3.1

7.1

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions mcp Python SDK versions prior to 1.27.2
Description Principal confusion exists in the HTTP transports of the mcp Python SDK. Specifically, the SSE and Streamable HTTP stateful mode routed sessions fail to verify if the principal matches the session creator. This allows an attacker who possesses a session ID to hijack the session.
Recommendations Update to version 1.27.2.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-52869
ECHO-5DA5-33DB-F402
GHSA-JPW9-PFVF-9F58
PYSEC-2026-3482

Affected Products

Mcp Python Sdk