NONE · 0

CVE-2026-67431

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem does not bind a session ID to a s...

Vulnerability Description

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem does not bind a session ID to a session owner, allowing an attacker with a stolen session ID to send tools/call requests that execute in the victim's session. This issue is fixed in version 0.23.0.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-67431?

CVE-2026-67431 is a documented vulnerability. MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem does not bind a session ID to a s...

How severe is CVE-2026-67431?

CVSS scoring is not yet available for CVE-2026-67431. Check NVD for updates.

Is there a patch for CVE-2026-67431?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.