Количество 2
Количество 2
CVE-2026-67431
MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem does not bind a session ID to a session owner, allowing an attacker with a stolen session ID to send tools/call requests that execute in the victim's session. This issue is fixed in version 0.23.0.
GHSA-5p9g-j988-pcwv
MCP Ruby SDK: Ruby SSE Session Poisoning
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-67431 MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem does not bind a session ID to a session owner, allowing an attacker with a stolen session ID to send tools/call requests that execute in the victim's session. This issue is fixed in version 0.23.0. | 0% Низкий | 8 дней назад | ||
GHSA-5p9g-j988-pcwv MCP Ruby SDK: Ruby SSE Session Poisoning | 0% Низкий | 7 дней назад |
Уязвимостей на страницу