CVE-2026-52869CVE-2026-52870MCP Python SDK session hijack and cross-session task access
Two flaws in the MCP Python SDK allowed session hijacking and access to tasks that belonged to other sessions. Both are fixed in version 1.27.2 of the SDK.
What happened
Advisory GHSA-JPW9-PFVF-9F58, published on 5 June 2026, covers two flaws in the MCP Python SDK. CVE-2026-52869 allowed session hijacking, and CVE-2026-52870 allowed access to tasks that belonged to other sessions.
Both are fixed in version 1.27.2.
Why it worked
Both flaws come down to the same gap. A session or task must belong to the authenticated principal that created it, and the server has to check that ownership on every request.
What to do
- Update the MCP Python SDK to 1.27.2 or later.
- Bind every session and task to the authenticated user and check ownership on each request.
- Treat session ids as identifiers, not as proof of identity.
- Run one server and transport instance per session where you can.
Isolate MCP sessions and tenants
Work through the security checklist →