cbcvebase.
CVE-2026-52869
published 2026-07-15

CVE-2026-52869: The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2, the SSE and stateful Streamable HTTP…

PriorityP341high7.1CVSS 3.1
AVNACHPRLUINSUCHIHAL
EPSS
0.53%
44.1th percentile
The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2, the SSE and stateful Streamable HTTP transports mcp.server.sse.SseServerTransport and mcp.server.streamable_http_manager.StreamableHTTPSessionManager route requests to existing sessions using only the session_id query parameter or Mcp-Session-Id header without verifying the authenticated principal that created the session, allowing a different bearer-token-authenticated client with a known session ID to inject JSON-RPC messages into that session. This issue is fixed in version 1.27.2.

Affected

3 ranges
VendorProductVersion rangeFixed in
cienamcp>= 0 < 1.27.21.27.2
lfprojectsmcp_python_sdk< 1.27.21.27.2
modelcontextprotocolpython-sdk< 1.27.21.27.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.