MCP SDK Session Hijacking via Missing Principal Verification in SSE/Streamable HTTP Transport
highAgentProtocol VulnerabilityThe MCP Python SDK's SSE and stateful Streamable HTTP transports route messages to sessions based solely on a session ID, without checking that the requesting client is the same authenticated principal who created that session. Any bearer-token-authenticated client that learns or guesses a valid session ID can inject JSON-RPC messages into another user's active session, effectively hijacking it. This is a serious cross-tenant authorization flaw fixed in version 1.27.2.
Updated Jul 16, 2026 · CVSS 7.1