CVE-2026-55604
Cross-Session Data Exposure via Caller-Controlled session_id
Project / Repository: arikusi/deepseek-mcp-server
Affected version / commit tested: 1.6.0 / 04f28be2c6e99d3d4e443a6ae37cc35f0a71554a
Vulnerability type: Authorization bypass / cross-session data exposure
Authentication required: No
Summary
The process-global SessionStore accepts caller-supplied session_id values without binding them to any authenticated principal or transport session. An attacker can enumerate active session IDs via deepseek_sessions, then reuse a victim-controlled session_id in deepseek_chat to retrieve and continue the victim's conversation context.
Affected Code
- src/session.ts:42 - caller-controlled session IDs are looked up directly from the global in-memory map.
- src/session.ts:67 - a new session is stored under the caller-controlled ID without ownership binding.
- src/session.ts:109 - getMessages() retrieves messages for any supplied session ID.
- src/tools/deepseek-chat.ts:195 - deepseek_chat creates or reuses the supplied session_id.
- src/tools/deepseek-chat.ts:197 - previous messages are loaded from the supplied session_id.
- src/tools/deepseek-chat.ts:198 - previous messages are prepended into the attacker-controlled request.
- src/tools/deepseek-chat.ts:243 - attacker-provided user messages are appended into the reused session.
- src/tools/deepseek-chat.ts:245 - assistant responses are appended back into the reused session.
- src/tools/deepseek-sessions.ts:37 - deepseek_sessions list enumerates all active sessions.
- src/tools/deepseek-sessions.ts:53 - each enumerated session ID is rendered back to the caller.
PoC Overview
1. Create a victim conversation with session_id = "victim-session".
2. Call deepseek_sessions with action = "list" and observe that victim-session is disclosed.
3. Call deepseek_chat again with session_id = "victim-session" from a separate attacker flow.
4. The upstream request now includes the victim's prior messages before the attacker's message.
Va
⚡ Watch CVE-2026-55604
Get an email if CVE-2026-55604 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all EPSS-scored CVEs.
Advisory coverage (2)
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-55604)