Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-55604

Опубликовано: 09 июл. 2026
Источник: nvd
CVSS3: 8.6
EPSS Низкий

Описание

DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to version 1.7.0, the process-global SessionStore accepts caller-supplied session_id values without binding them to any authenticated principal or transport session. An attacker can enumerate active session IDs via deepseek_sessions, then reuse a victim-controlled session_id in deepseek_chat to retrieve and continue the victim's conversation context. Version 1.7.0 contains a patch.

EPSS

Процентиль: 30%
0.00372
Низкий

8.6 High

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 8.6
github
22 дня назад

@arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key

EPSS

Процентиль: 30%
0.00372
Низкий

8.6 High

CVSS3

Дефекты

CWE-639