CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-55604

highCVSS 8.6covered by 2 sourcesfirst seen 2026-07-09
Cross-Session Data Exposure via Caller-Controlled session_id Project / Repository: arikusi/deepseek-mcp-server Affected version / commit tested: 1.6.0 / 04f28be2c6e99d3d4e443a6ae37cc35f0a71554a Vulnerability type: Authorization bypass / cross-session data exposure Authentication required: No Summary The process-global SessionStore accepts caller-supplied session_id values without binding them to any authenticated principal or transport session. An attacker can enumerate active session IDs via deepseek_sessions, then reuse a victim-controlled session_id in deepseek_chat to retrieve and continue the victim's conversation context. Affected Code - src/session.ts:42 - caller-controlled session IDs are looked up directly from the global in-memory map. - src/session.ts:67 - a new session is stored under the caller-controlled ID without ownership binding. - src/session.ts:109 - getMessages() retrieves messages for any supplied session ID. - src/tools/deepseek-chat.ts:195 - deepseek_chat creates or reuses the supplied session_id. - src/tools/deepseek-chat.ts:197 - previous messages are loaded from the supplied session_id. - src/tools/deepseek-chat.ts:198 - previous messages are prepended into the attacker-controlled request. - src/tools/deepseek-chat.ts:243 - attacker-provided user messages are appended into the reused session. - src/tools/deepseek-chat.ts:245 - assistant responses are appended back into the reused session. - src/tools/deepseek-sessions.ts:37 - deepseek_sessions list enumerates all active sessions. - src/tools/deepseek-sessions.ts:53 - each enumerated session ID is rendered back to the caller. PoC Overview 1. Create a victim conversation with session_id = "victim-session". 2. Call deepseek_sessions with action = "list" and observe that victim-session is disclosed. 3. Call deepseek_chat again with session_id = "victim-session" from a separate attacker flow. 4. The upstream request now includes the victim's prior messages before the attacker's message. Va

⚡ Watch CVE-2026-55604

Get an email if CVE-2026-55604 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-55604

CVE.org record

Embed the live status

CVE-2026-55604 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-55604 status](https://www.csirts.com/badge/CVE-2026-55604)](https://www.csirts.com/cve/CVE-2026-55604)