PT-2026-53226 · Pypi · Mcp Python Sdk

CVE-2026-52870

·

Published

2026-06-27

·

Updated

2026-07-27

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions MCP Python SDK versions prior to 1.27.2
Description A missing authorization issue exists in the official Model Context Protocol Python SDK. On multi-client servers, the default request handlers registered by the experimental enable tasks() helper do not verify the identity of the caller, relying solely on task IDs and storing active workflows in a single global server store. This allows any authenticated client to enumerate, read, and hijack or cancel tasks belonging to other clients.
Recommendations Update to version 1.27.2 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-52870
ECHO-686F-4B2A-3DD3
GHSA-HVRP-RF83-W775
PYSEC-2026-3481

Affected Products

Mcp Python Sdk