CVE-2026-52870
published 2026-07-15CVE-2026-52870: The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed by…
PriorityP344high7.6CVSS 3.1
AVNACLPRLUINSUCHILAL
EPSS
0.39%
30.5th percentile
The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed by server.experimental.enable_tasks() for tasks/list, tasks/get, tasks/result, and tasks/cancel operate only on task identifiers without recording the session that created each task, allowing any connected client to enumerate, read results from, consume messages for, or cancel other clients' tasks. This issue is fixed in version 1.27.2.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ciena | mcp | >= 1.23.0 < 1.27.2 | 1.27.2 |
| lfprojects | mcp_python_sdk | >= 1.23.0 < 1.27.2 | 1.27.2 |
| modelcontextprotocol | python-sdk | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks
ghsa·2026-07-16
CVE-2026-52870 [HIGH] CWE-862 MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks
MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks
### Summary
In affected versions, the default request handlers installed by the experimental tasks feature (`server.experimental.enable_tasks()`) did not check which session created a task before acting on it. On a server with more than one connected client, any client could observe, read results from, and cancel tasks belonging to other clients.
### Am I affected?
Only if the developer's application server calls `server.experimental.enable_tasks()`. If `grep -r enable_tasks` over their codebase finds nothing, the application is not affected.
### Details
When tasks support is enabled on the low-level server, default handlers are registered for `tasks/list`, `tasks/get`, `tasks/result`,
VulDB
modelcontextprotocol python-sdk up to 1.27.1 Task Management server.experimental.enable_tasks information disclosure
vuldb·2026-07-15·CVSS 7.6
CVE-2026-52870 [HIGH] modelcontextprotocol python-sdk up to 1.27.1 Task Management server.experimental.enable_tasks information disclosure
A vulnerability labeled as problematic has been found in modelcontextprotocol python-sdk up to 1.27.1. The affected element is the function server.experimental.enable_tasks of the component Task Management. Executing a manipulation can lead to information disclosure.
This vulnerability is handled as CVE-2026-52870. The attack can be executed remotely. There is not any exploit available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/modelcontextprotocol/python-sdk/commit/62137874ff26dd74d2fea80ff528a7fd9ca7a5e7https://github.com/modelcontextprotocol/python-sdk/pull/2720https://github.com/modelcontextprotocol/python-sdk/releases/tag/v1.27.2https://github.com/modelcontextprotocol/python-sdk/security/advisories/GHSA-hvrp-rf83-w775
2026-07-15
Published