CVE-2026-33946Patch(lfprojects / mcp_ruby_sdk)

LOWCVSS 5.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch lfprojects mcp_ruby_sdk systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to version 0.9.2, the Ruby SDK's streamable_http_transport.rb implementation contains a session hijacking vulnerability. An attacker who obtains a valid session ID can completely hijack the victim's Server-Sent Events (SSE) stream and intercept all real-time data. Version 0.9.2 contains a patch.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-384CWE-639

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mcp_ruby_sdk

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-28); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
mcp_ruby_sdk

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-28: 1Mentions · 2026-03-30: 1Mentions · 2026-04-28: 1Patch / Workaround · 2026-03-28: 1Patch / Workaround · 2026-04-28: 1Technical Details · 2026-03-30: 103-2803-3004-28
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-281
Patch1
2026-03-301
Disclosure1
2026-04-281
Patch1
Full discourse3 posts
  • How2claude Japanese@how2claude_ja
    Patch

    一気にやってくれたこと: → RuboCop 違反 63 → 0 → ついでに mcp gem の CVE-2026-33946 を patch(bundler-audit の警告を見て持ってきた) → postgres:17 の service container を追加 頼んだのは 1 つ。返ってきたのは 4 つ。

    Post summary

    The post indicates that the mcp gem CVE-2026-33946 was patched, but provides no further details on the vulnerability, exploit, or broader context.

    1000042
    8 followersView on X
  • RUBYLAND@rubylandnews
    Disclosure

    RubySec ➜ CVE-2026-33946 (mcp): MCP Ruby SDK - Insufficient Session Binding Allows SSE Stream Hijacking via Session ID Replay https://rubysec.com/advisories/CVE-2026-33946/

    Post summary

    RubySec has disclosed CVE-2026-33946, highlighting that insufficient session binding in the MCP Ruby SDK can lead to SSE stream hijacking through session ID replay.

    0000090
    2.7K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-33946 MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to version 0.9.2, the Ruby SDK's streamable_http_transport.rb implementati… https://www.cve.org/CVERecord?id=CVE-2026-33946

    Post summary

    The Ruby SDK before v0.9.2 is vulnerable per CVE-2026-33946; upgrading to v0.9.2 resolves the issue.

    00000222
    56.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applfprojectsmcp_ruby_sdk---

Explore more