CVE-2026-67431
### Summary **Vulnerability**: Missing Session Ownership Validation in the Ruby MCP SDK's Streamable and SSE HTTP transport implementation. Any attacker with a stolen session ID can execute tools with the victim's session. This is a silent attack - the victim's session is compromised and being used for unauthorized actions, but it is hard to know for the victim ### Details https://github.com/modelcontextprotocol/ruby-sdk/blob/main/lib/mcp/server/transports/streamable_http_transport.rb#L260-L278 **Victim** starts a legitimate MCP session and receives session ID abc-123 **Attacker** obtains the session ID (various means - network sniffing, logs, etc. out of scope for this analysis) **Attacker** sends POST to /messages/abc-123 with a tool call **Server** accepts the request (no ownership validation!) **Server** executes the tool and sends response to victim's SSE stream **Victim** receives attacker's response, thinking it's legitimate ### PoC [attacker_client.py](https://github.com/user-attachments/files/26044817/attacker_client.py) [legitimate_client.py](https://github.com/user-attachments/files/26044818/legitimate_client.py) **Prerequisites** 1. Python 3.8+ 2. Install dependencies: `requests` **Running the Demo** 1. **Terminal 1:** Start the Ruby MCP Server `ruby streamable_http_server.rb` Makes use of https://github.com/modelcontextprotocol/ruby-sdk/blob/main/examples/streamable_http_server.rb This server has a tool call notification_tool which the clients call 2. **Terminal 2:** Start Victim Client `python3 legitimate_client.py` 3. **Terminal 3** - Attacker Client: Copy the session ID from Terminal 1 and run: ```bash python3 attacker_client.py abc-123-def-456 ``` 4. **Back to Terminal 2** - Victim sees the injected response: ### Impact - **Integrity:** HIGH - Attacker can execute unauthorized tools and modify state - **Availability:** LOW - Attacker can disrupt victim's session with injected responses ### Additional Details Session Hijacking Prot
Properties
- ghsa_id
- GHSA-5p9g-j988-pcwv
- severity
- high
- summary
- MCP Ruby SDK: Ruby SSE Session Poisoning
- epss_score
- 0.00292
- cve_id
- CVE-2026-67431
- signal_observed_at
- 2026-09-11T17:55:57+00:00
- is_ghsa_only
- false
- ghsa_published
- 2026-07-30T14:44:28Z
- source_url
- https://github.com/advisories/GHSA-5p9g-j988-pcwv
- epss_percentile
- 0.21682
- ghsa_updated
- 2026-07-30T14:44:29Z
Related Entities (5)
ENRICHED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph