CVE-2026-52870General(lfprojects / mcp_python_sdk)

LOWCVSS 7.6 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch lfprojects mcp_python_sdk systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed by server.experimental.enable_tasks() for tasks/list, tasks/get, tasks/result, and tasks/cancel operate only on task identifiers without recording the session that created each task, allowing any connected client to enumerate, read results from, consume messages for, or cancel other clients' tasks. This issue is fixed in version 1.27.2.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mcp_python_sdk

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-07-15)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
mcp_python_sdk

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-27: 1Mentions · 2026-07-15: 2PoC Mentioned / Linked · 2026-06-27: 1Patch / Workaround · 2026-06-27: 1Technical Details · 2026-06-27: 106-2707-15
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-271
Disclosure1
2026-07-152
General2
Full discourse3 posts
  • Dewank Pant@secyourity
    Disclosure

    Published our new research: CVE-2026-52870 (Missing Authorization) in @AnthropicAI's MCP Python SDK. On multi-client MCP servers, any authenticated client could enumerate and hijack tasks from other clients. Patched in v1.27.2. https://medium.com/@shrutilohani9/stealing-the-keys-to-the-agentic-cloud-critical-authorization-flaw-in-anthropics-mcp-sdk-6a4bb74bead2 @Shruti__Lohani

    Post summary

    A new authorization flaw (CVE-2026-52870) in Anthropic’s MCP Python SDK lets authenticated users enumerate and hijack tasks across clients; the issue has been patched in v1.27.2.

    1001054
    56 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-52870 The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed by server… https://www.cve.org/CVERecord?id=CVE-2026-52870

    Post summary

    The text references the CVE ID and links to its record but provides no further details on the vulnerability, exploitation, or mitigation.

    00010803
    57.8K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-52870 The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed by server… https://www.cve.org/CVERecord?id=CVE-2026-52870 ----- Traducción: CVE-2026-52870 El … http://infoflow.cloud`

    Post summary

    The tweet references CVE-2026-52870 for the MCP Python SDK, listing affected versions, but offers no evidence of exploitation, patches, or PoC—it is essentially an announcement.

    0000035
    92 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applfprojectsmcp_python_sdk---

Explore more