
🚨High - DeepSeek MCP Server Session Hijack via User-Controlled session_id (CVE-2026-55604) DeepSeek MCP Server's process-global SessionStore accepts caller-supplied session_id values without binding them to any authenticated principal or transport session. An attacker can enumerate active session IDs via the deepseek_sessions tool, then reuse a victim's session_id in deepseek_chat. That lets the attacker retrieve and continue another user's conversation context - reading their chat history and hijacking the session. It's an IDOR/authorization-bypass (CWE-639) with high confidentiality impact, most dangerous in shared multi-user MCP deployments. 👉Upgrade DeepSeek MCP Server to 1.7.0.
Post summary
The post announces the discovery of a session hijacking vulnerability (CVE-2026-55604) in DeepSeek MCP Server, details its exploitation technique via session ID enumeration, and advises users to upgrade to version 1.7.0 to mitigate the issue.
