
CVE-2026-48529: GitHub MCP Server HTTP lockdown-mode singleton can mix users’ GraphQL clients In HTTP mode with --lockdown-mode, a process-global RepoAccessCache singleton can be initialized with the first user’s authenticated GraphQL client and then reused for later users’ requests, creating a cross-user trust-boundary failure via shared server state. #MCP #AgentSecurity #AISecurity #Advisory https://github.com/advisories/GHSA-pjp5-fpmr-3349
Post summary
An advisory discloses a cross‑user trust‑boundary flaw in GitHub MCP Server’s HTTP lockdown‑mode, where a process‑global singleton can leak GraphQL client state between users.

