CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-67431

CVE-2026-67431: Session Poisoning via Improper Access Control in Model Context Protocol Ruby SDK

Alon Barad
Alon Barad
Software Engineer

Jul 31, 2026·7 min read·66 visits

Executive Summary (TL;DR)

A lack of session binding in the MCP Ruby SDK allows remote attackers possessing a valid session ID to execute arbitrary tool calls and manipulate session states.

An Improper Access Control vulnerability exists in the Model Context Protocol (MCP) Ruby SDK prior to version 0.23.0. The stateful transport implementation failed to bind established sessions to their original owners or connection contexts, enabling unauthorized actors with access to active session IDs to execute arbitrary tools or alter session state.

Vulnerability Overview

The Model Context Protocol (MCP) defines an open standard for secure interaction between clients (such as local large language model integrations) and host servers that expose local capabilities. The mcp gem is the official SDK providing the scaffolding for building these clients and servers in Ruby environments. Within this SDK, transport adapters handle the serialization and transmission of JSON-RPC 2.0 messages. One such adapter is the MCP::Server::Transports::StreamableHTTPTransport, which implements a stateful HTTP server layout.

In stateful HTTP mode, the communication model is split. The client initiates a unidirectional Server-Sent Events (SSE) downstream channel over a long-lived GET connection. Upon initialization, the server creates a stateful session tracked in its memory registry and assigns a unique identifier. Upstream communication from the client (such as initiating tool calls, publishing configuration resources, or sending notifications) is handled via stateless HTTP POST requests referencing this session identifier.

The vulnerability, tracked as CVE-2026-67431, represents a class of Improper Access Control (CWE-284) where the transport server accepts state-changing POST requests without validating that the sender of the request actually owns the associated session. This design allows any network-adjacent or external attacker who captures a valid session ID to interact with the target session. The underlying server then processes the attacker's instructions within the security context of the victim's session.

Root Cause Analysis

The technical root cause of CVE-2026-67431 lies in the complete absence of session-to-connection binding inside StreamableHTTPTransport. When a client initiates a session via an SSE connection, the transport server registers the session ID inside an internal hash-map. The structure keeps track of the underlying SSE write stream, the initialization timestamp, and inactivity states. However, the transport layer does not establish any link with the TCP socket or authentication credentials to verify subsequent requests.

Subsequent HTTP requests (POST, GET, and DELETE) that execute against an existing session must supply the session identifier. The SDK retrieves this identifier using the Mcp-Session-Id header. The server's validation sequence checks only that the incoming session ID is registered within the hash-map and that the session has not exceeded its inactivity window. It does not perform any authorization checks.

Because HTTP is a stateless protocol and the SSE down-channel is independent of the upstream POST path, any HTTP client can dispatch a request to /messages specifying any active session ID. The server validates the session's active status and executes the requested operation. The server then transmits the JSON-RPC response through the victim's SSE stream. This design leads to SSE session poisoning, allowing an attacker to inject execution blocks and state alterations into a client's active process.

Code-Level Vulnerability & Patch Analysis

Before the release of version 0.23.0, the handle_post method in the transport routed incoming JSON-RPC payloads based on existence checks of the session ID. The code did not verify request origins or require custom authorization logic. This exposed stateful servers to arbitrary request execution.

# Pre-0.23.0 logic in StreamableHTTPTransport (Vulnerable)
def handle_post(request)
  session_id = extract_session_id(request)
  if session_id.nil? || !@sessions.key?(session_id)
    return bad_request_response
  end
  # Lack of owner verification here allows unauthorized dispatch
  body = parse_request_body(request)
  dispatch_rpc_message(body, session_id)
end

The remediation introduced in commit 35466605319a34e4c7808712ae9bb1ca1afb2356 establishes two layers of defensive checks. First, during the initial GET handshake that establishes the SSE stream, the transport captures the client's HTTP_ORIGIN header and stores it in the session metadata hash. Second, it implements a helper method validate_session_request that matches incoming requests against this origin. More importantly, the patch implements a configuration hook, session_request_validator, which allows developers to execute a customized authorization procedure.

# Patched validation logic in StreamableHTTPTransport (0.23.0)
def validate_session_request(request, session_id)
  session = @mutex.synchronize { @sessions[session_id] }
  return true unless session
 
  session_origin = session[:origin]
  request_origin = request.env["HTTP_ORIGIN"]
  # Reject if origin headers do not match
  return false if session_origin && request_origin && session_origin != request_origin
 
  # Execute application-level callback for comprehensive identity binding
  return @session_request_validator.call(request, session_id) if @session_request_validator
 
  true
end

Exploitation Methodology

Exploitation of CVE-2026-67431 depends on the attacker acquiring a valid session ID. Because the SDK implements high-entropy identifiers using UUIDs, direct brute-forcing of the session space is mathematically impractical. Instead, attackers must acquire active session keys via secondary vectors, such as insecure logging configurations, lack of encryption over local loopback connections, or side-channel exposures in shared multi-user systems.

Once an active session identifier is acquired, the exploitation proceeds in a stateless manner. The attacker crafts a standard HTTP POST request directed at the target MCP server endpoint. The payload is framed as a standard JSON-RPC 2.0 object targeting registered backend tools. For example, the attacker might target a command execution tool exposed by the host.

curl -X POST http://mcp-server-host:9292/messages \
  -H "Mcp-Session-Id: d3b07384-d113-40a2-a8b4-02ede36dbf5f" \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc": "2.0", "method": "tools/call", "id": 101, "params": {"name": "read_file", "arguments": {"path": "/etc/passwd"}}}'

Upon receiving this request, the vulnerable MCP server verifies that the session identifier exists. Finding a match, it routes the command to the backend tool. The output is processed and returned over the SSE stream to the victim client. While the attacker does not receive the command output directly within the POST response body, they succeed in executing the action. Additionally, they can send notifications/cancelled to abort the victim's current actions, leading to denial of service.

Impact Assessment

The severity rating for CVE-2026-67431 is High, with a CVSS v4.0 base score of 8.3. The vector breakdown highlights that the attack vector is Network (AV:N), and the attack complexity is Low (AC:L). The primary threat is the high impact on integrity (VI:H). An attacker can run state-changing commands on behalf of the victim's session.

The actual impact in production environments depends on the tools exposed by the MCP server. If the server implements filesystem operations, database queries, or command-line execution interfaces, the attacker gains full access to these capabilities. This can lead to local privilege escalation, unauthorized system modifications, or lateral network movement.

Because the execution results are streamed only to the victim's active SSE connection, the direct confidentiality impact is technically rated as None (VC:N) at the transport layer. However, the attacker can cause indirect confidentiality loss by writing sensitive information to files, sending data to external endpoints, or manipulating downstream AI model contexts to exfiltrate data via prompt injection.

Remediation & Defense-in-Depth

Securing environments against CVE-2026-67431 requires an immediate upgrade and explicit configuration. Operators must update the mcp gem to version 0.23.0 or higher. Running the updated SDK is the foundation of the fix, but configuration adjustments are necessary to ensure complete remediation.

# Gemfile requirement
gem 'mcp', '>= 0.23.0'

Because the StreamableHTTPTransport does not inherently understand application-level user identities, upgrading the gem only enables the origin-matching defense. This check can be bypassed by non-browser clients. To fully mitigate the vulnerability, developers must instantiate the transport with a custom session_request_validator hook that correlates the HTTP request session state (such as cookies or tokens) with the MCP session.

# Secure transport instantiating pattern
transport = MCP::Server::Transports::StreamableHTTPTransport.new(
  server,
  session_request_validator: ->(request, session_id) {
    # Extract session owner identity from secure cookie
    session_user_id = request.env['rack.session'][:user_id]
    expected_owner_id = Database.get_mcp_session_owner(session_id)
    
    # Restrict execution to the actual owner
    session_user_id == expected_owner_id
  }
)

In environments where stateful session tracking is not strictly required, operators can eliminate the attack surface by transitioning to the stateless transport mode. This can be configured by setting the stateless parameter to true. This action disables session generation entirely, requiring every transaction to validate independently.

Fix Analysis (1)

Technical Appendix

CVSS Score
8.3/ 10
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
EPSS Probability
0.28%
Top 80% most exploited

Affected Systems

mcp (RubyGems)Model Context Protocol Ruby SDK

Affected Versions Detail

Product
Affected Versions
Fixed Version
mcp
modelcontextprotocol
< 0.23.00.23.0
AttributeDetail
CWE IDCWE-284
Attack VectorNetwork (AV:N)
CVSS v4.0 Score8.3
EPSS Score0.00276
Exploit StatusPOC (in official repository tests)
KEV StatusNot Listed
ImpactHigh Integrity, Low Availability

MITRE ATT&CK Mapping

T1563.001Session Hijacking: Web Session Hijacking
Lateral Movement
T1190Exploit Public-Facing Application
Initial Access
CWE-284
Improper Access Control

The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Vulnerability Timeline

Session-Ownership Hook patch committed (35466605319a34e4c7808712ae9bb1ca1afb2356)
2026-07-07
Official release of version 0.23.0 containing the session-ownership fixes
2026-07-07
CVE-2026-67431 is published in the CVE and GitHub Advisory databases
2026-07-29

References & Sources

  • [1]https://www.cve.org/CVERecord?id=CVE-2026-67431
  • [2]https://github.com/modelcontextprotocol/ruby-sdk/security/advisories/GHSA-5p9g-j988-pcwv
  • [3]https://github.com/modelcontextprotocol/ruby-sdk/commit/35466605319a34e4c7808712ae9bb1ca1afb2356
  • [4]https://github.com/modelcontextprotocol/ruby-sdk/releases/tag/v0.23.0
  • [5]https://nvd.nist.gov/vuln/detail/CVE-2026-67431

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•28 minutes ago•CVE-2026-104861
7.5

CVE-2026-104861: Quadratic-time Regular Expression Denial of Service in probe-image-size SVG Parser

An uncontrolled resource consumption vulnerability (CWE-1333 / CWE-400) exists in probe-image-size versions prior to 7.4.0. The SVG parser utilizes an unanchored, inefficient regular expression to find the SVG root tag, leading to catastrophic backtracking when handling malformed payloads. This blocks the single-threaded Node.js event loop, resulting in a complete denial of service.

Amit Schendel
Amit Schendel
3 views•9 min read
•about 1 hour ago•CVE-2026-10032
6.1

CVE-2026-10032: DOM-based Cross-Site Scripting (XSS) via window.open in Google @a2ui/web_core

CVE-2026-10032 is a DOM-based Cross-Site Scripting (XSS) vulnerability in Google's @a2ui/web_core Node.js library. The vulnerability is located within the openUrl utility function, which processes and opens dynamic URLs defined in layout configurations. Because the function fails to sanitize or validate the target URL scheme before passing it to the window.open browser sink, an attacker can specify a javascript: pseudo-protocol to execute arbitrary client-side script in the context of the host origin.

Amit Schendel
Amit Schendel
6 views•7 min read
•about 2 hours ago•CVE-2026-59944
6.1

CVE-2026-59944: Path Traversal and Symlink Resolution Bypass in Composer

CVE-2026-59944 is a path traversal and link-following vulnerability in Composer, the PHP dependency manager. This flaw allows malicious or compromised packages to bypass previous path-hardening protections and perform arbitrary filesystem operations outside of their designated installation directory, leading to unauthorized permission modifications or execution proxy creations.

Amit Schendel
Amit Schendel
6 views•6 min read
•about 3 hours ago•GHSA-QXPP-QJG8-X4JV
9.9

GHSA-QXPP-QJG8-X4JV: Cross-Tenant Run Replay and Task Injection in Trigger.dev

A critical Broken Object Level Authorization (BOLA) vulnerability was identified in Trigger.dev before version v4.5.2. An authenticated attacker could trigger a run replay and supply an arbitrary target environmentId belonging to a completely different tenant. Because the server failed to validate whether the target environment belonged to the same project or organization as the source run, it would execute the task within the victim's environment, resulting in unauthorized cross-tenant write operations and remote task execution.

Alon Barad
Alon Barad
10 views•5 min read
•about 4 hours ago•GHSA-XXV7-2VV3-H682
7.7

CVE-2026-85650: Server-Side Request Forgery in Trigger.dev Webhook Alert Channel Delivery

A critical Server-Side Request Forgery (SSRF) vulnerability in Trigger.dev prior to version 4.5.2 allows authenticated organization members to configure webhook alert channels with unvalidated target URLs. This can lead to internal network scanning and cloud metadata extraction.

Alon Barad
Alon Barad
9 views•7 min read
•about 7 hours ago•GHSA-C9XM-49CP-XCR9
6.3

GHSA-C9XM-49CP-XCR9: Server-Side Request Forgery in rmcp OAuth Client

A Server-Side Request Forgery (SSRF) vulnerability exists in the rmcp OAuth client, which is part of the Model Context Protocol (MCP) Rust SDK. The vulnerability arises from insecure processing of the resource_metadata parameter in WWW-Authenticate headers returned by a malicious or compromised MCP server. The client parses and fetches absolute URLs from this header without validation of scheme, origin, or network routing, allowing remote attackers to initiate HTTP GET requests to local network interfaces, RFC 1918 private subnets, or cloud metadata endpoints.

Alon Barad
Alon Barad
8 views•6 min read