CVE-2026-52869Patch(lfprojects / mcp_python_sdk)

LOWCVSS 7.1 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch lfprojects mcp_python_sdk systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2, the SSE and stateful Streamable HTTP transports mcp.server.sse.SseServerTransport and mcp.server.streamable_http_manager.StreamableHTTPSessionManager route requests to existing sessions using only the session_id query parameter or Mcp-Session-Id header without verifying the authenticated principal that created the session, allowing a different bearer-token-authenticated client with a known session ID to inject JSON-RPC messages into that session. This issue is fixed in version 1.27.2.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mcp_python_sdk

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-07-15); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
mcp_python_sdk

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-06-27: 1Mentions · 2026-06-28: 1Mentions · 2026-07-15: 2Mentions · 2026-08-22: 1Mentions · 2026-09-05: 1PoC Mentioned / Linked · 2026-06-27: 1Patch / Workaround · 2026-06-28: 1Patch / Workaround · 2026-07-15: 1Patch / Workaround · 2026-08-22: 1Technical Details · 2026-06-27: 1Technical Details · 2026-06-28: 1Technical Details · 2026-08-22: 106-2706-2807-1508-2209-05
Signal classification3 categories
Patch
350.0%
General
233.3%
Disclosure
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-06-271
Disclosure1
2026-06-281
Patch1
2026-07-152
General1Patch1
2026-08-221
Patch1
2026-09-051
General1
Full discourse6 posts
  • 7h3h4ckv157@7h3h4ckv157
    Disclosure

    Anthropic CVE-2026-52869: A Session ID Is Not a Credential Principal Confusion in the MCP Python SDK’s HTTP Transports Author: HE WEI (ギ カク) Read: https://skypoc.wordpress.com/2026/06/10/cve-2026-52869/

    Post summary

    The post announces CVE‑2026‑52869, describing a credential confusion flaw in Anthropic’s MCP Python SDK, and provides a link for further details.

    110164217.4K
    56.2K followersView on X
  • 諏訪真一 / IT部門のジェネラリスト@suwa_sh
    General

    原則3は最小権限。Agent Identity、3LO、Principal Access Boundary、Agent Gateway と権限側は整備が進む。ただし減衰トークンは無い。設計に進む前に、MCP Python SDK を 1.27.2 以上へ固定する。CVE-2026-52869 の対象になる。

    Post summary

    The text is a brief advisory recommending upgrading the MCP Python SDK to mitigate CVE‑2026‑52869, with no additional exploit or patch details.

    1000052
    520 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-52869 The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2, the SSE and stateful Streamable HTTP transpor… https://www.cve.org/CVERecord?id=CVE-2026-52869

    Post summary

    This CVE concerns a vulnerability in the MCP Python SDK, with a fix available in version 1.27.2, but the excerpt offers no PoC, exploit code, or active exploitation evidence.

    000101.0K
    57.8K followersView on X
  • Victor@VMG_CU
    Patch

    Builder note from CVE-2026-52869 (MCP Python SDK): If your transport looks up sessions by ID alone, auth doesn't isolate clients. Bind the principal. Patch ≥1.27.2. https://github.com/modelcontextprotocol/python-sdk/security/advisories/GHSA-jpw9-pfvf-9f58

    Post summary

    The advisory announces a session isolation flaw in MCP Python SDK and recommends upgrading to version 1.27.2 or later for a fix.

    0000044
    14 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-52869 The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2, the SSE and stateful Streamable HTTP transpor… https://www.cve.org/CVERecord?id=CVE-2026-52869 ----- Traducción: CVE-2026-52869 El … http://infoflow.cloud`

    Post summary

    The tweet briefly mentions CVE‑2026‑52869 affecting the MCP Python SDK, noting a vulnerability in older versions, but does not provide detailed technical information, exploitation evidence, or mitigation guidance.

    0000049
    92 followersView on X
  • pulpmatrix@pulpmatrix
    Patch

    Confirmed. CVE-2026-52869: mcp Python SDK SSE and Streamable HTTP stateful mode routed sessions without checking the principal matched the creator. Anyone with the session ID could hijack it. Patched in 1.27.2 by binding to OAuth c... https://x.com/i/status/2070872953148047607

    Post summary

    The post confirms CVE-2026-52869, a session hijacking flaw in the MCP Python SDK, and notes it was patched in version 1.27.2.

    0000088
    18 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applfprojectsmcp_python_sdk---

Explore more