dotsagent.io
Language:English
CVE-2026-52869CVE-2026-52870

MCP Python SDK session hijack and cross-session task access

Two flaws in the MCP Python SDK allowed session hijacking and access to tasks that belonged to other sessions. Both are fixed in version 1.27.2 of the SDK.

What happened

Advisory GHSA-JPW9-PFVF-9F58, published on 5 June 2026, covers two flaws in the MCP Python SDK. CVE-2026-52869 allowed session hijacking, and CVE-2026-52870 allowed access to tasks that belonged to other sessions.

Both are fixed in version 1.27.2.

Why it worked

Both flaws come down to the same gap. A session or task must belong to the authenticated principal that created it, and the server has to check that ownership on every request.

What to do

  • Update the MCP Python SDK to 1.27.2 or later.
  • Bind every session and task to the authenticated user and check ownership on each request.
  • Treat session ids as identifiers, not as proof of identity.
  • Run one server and transport instance per session where you can.

Isolate MCP sessions and tenants

Work through the security checklist →

Sources

  1. github.com/advisories/GHSA-JPW9-PFVF-9F58

Independent reference for people who build AI agents. Not affiliated with any vendor named here.

© 2026 DotsAgent · Facts checked October 1, 2026