highVulnerability

CVE-2026-67431

### Summary **Vulnerability**: Missing Session Ownership Validation in the Ruby MCP SDK's Streamable and SSE HTTP transport implementation. Any attacker with a stolen session ID can execute tools with the victim's session. This is a silent attack - the victim's session is compromised and being used for unauthorized actions, but it is hard to know for the victim ### Details https://github.com/modelcontextprotocol/ruby-sdk/blob/main/lib/mcp/server/transports/streamable_http_transport.rb#L260-L278 **Victim** starts a legitimate MCP session and receives session ID abc-123 **Attacker** obtains the session ID (various means - network sniffing, logs, etc. out of scope for this analysis) **Attacker** sends POST to /messages/abc-123 with a tool call **Server** accepts the request (no ownership validation!) **Server** executes the tool and sends response to victim's SSE stream **Victim** receives attacker's response, thinking it's legitimate ### PoC [attacker_client.py](https://github.com/user-attachments/files/26044817/attacker_client.py) [legitimate_client.py](https://github.com/user-attachments/files/26044818/legitimate_client.py) **Prerequisites** 1. Python 3.8+ 2. Install dependencies: `requests` **Running the Demo** 1. **Terminal 1:** Start the Ruby MCP Server `ruby streamable_http_server.rb` Makes use of https://github.com/modelcontextprotocol/ruby-sdk/blob/main/examples/streamable_http_server.rb This server has a tool call notification_tool which the clients call 2. **Terminal 2:** Start Victim Client `python3 legitimate_client.py` 3. **Terminal 3** - Attacker Client: Copy the session ID from Terminal 1 and run: ```bash python3 attacker_client.py abc-123-def-456 ``` 4. **Back to Terminal 2** - Victim sees the injected response: ### Impact - **Integrity:** HIGH - Attacker can execute unauthorized tools and modify state - **Availability:** LOW - Attacker can disrupt victim's session with injected responses ### Additional Details Session Hijacking Prot

Properties

ghsa_id
GHSA-5p9g-j988-pcwv
severity
high
summary
MCP Ruby SDK: Ruby SSE Session Poisoning
epss_score
0.00292
cve_id
CVE-2026-67431
signal_observed_at
2026-09-11T17:55:57+00:00
is_ghsa_only
false
ghsa_published
2026-07-30T14:44:28Z
source_url
https://github.com/advisories/GHSA-5p9g-j988-pcwv
epss_percentile
0.21682
ghsa_updated
2026-07-30T14:44:29Z

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

VULNERABLE_TO (1)

[Software]rubygems/mcp

AFFECTS (1)

[Software]rubygems/mcp

HAS_WEAKNESS (1)

[Weakness]Improper Access Control

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-67431 — Ninja Signal Threat Intelligence | Ninja Signal