cbcvebase.

Lfprojects Mcp Python Sdk vulnerabilities

4 known vulnerabilities affecting lfprojects/mcp_python_sdk.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4

Vulnerabilities

Page 1 of 1
CVE-2025-66416P3HIGHCVSS 8.1fixed in 1.23.02025-12-02
CVE-2025-66416 [HIGH] CWE-1188 CVE-2025-66416: The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol ( The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to version 1.23.0, tThe Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default for HTTP-based servers. When an HTTP-based MCP server is run on localhost without authentication using FastMCP with streamab
ghsanvdosv
CVE-2026-52870P3HIGHCVSS 7.6≥ 1.23.0, < 1.27.22026-07-15
CVE-2026-52870 [HIGH] CWE-862 CVE-2026-52870: The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MC The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed by server.experimental.enable_tasks() for tasks/list, tasks/get, tasks/result, and tasks/cancel operate only on task identifiers without recording the session that created each task, allowing any
nvd
CVE-2026-52869P3HIGHCVSS 7.1fixed in 1.27.22026-07-15
CVE-2026-52869 [HIGH] CWE-639 CVE-2026-52869: The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MC The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2, the SSE and stateful Streamable HTTP transports mcp.server.sse.SseServerTransport and mcp.server.streamable_http_manager.StreamableHTTPSessionManager route requests to existing sessions using only the session_id query parameter or M
nvd
CVE-2026-59950P3HIGHCVSS 8.1fixed in 1.28.12026-07-15
CVE-2026-59950 [HIGH] CWE-346 CVE-2026-59950: The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MC The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_server transport accepted WebSocket handshakes without applying Host or Origin header validation, leaving no SDK-level way to restrict which origins could connect to applications that ex
nvd
Lfprojects Mcp Python Sdk vulnerabilities | cvebase