CVE-2026-67431
Summary
Vulnerability: Missing Session Ownership Validation in the Ruby MCP SDK's Streamable and SSE HTTP transport implementation. Any attacker with a stolen session ID can execute tools with the victim's session. This is a silent attack - the victim's session is compromised and being used for unauthorized actions, but it is hard to know for the victim
Details
https://github.com/modelcontextprotocol/ruby-sdk/blob/main/lib/mcp/server/transports/streamable_http_transport.rb#L260-L278
Victim starts a legitimate MCP session and receives session ID abc-123
Attacker obtains the session ID (various means - network sniffing, logs, etc. out of scope for this analysis)
Attacker sends POST to /messages/abc-123 with a tool call
Server accepts the request (no ownership validation!)
Server executes the tool and sends response to victim's SSE stream
Victim receives attacker's response, thinking it's legitimate
PoC
attacker_client.py
legitimate_client.py
Prerequisites
1. Python 3.8+
2. Install dependencies: requests
Running the Demo
1. Terminal 1: Start the Ruby MCP Server
ruby streamable_http_server.rb
Makes use of https://github.com/modelcontextprotocol/ruby-sdk/blob/main/examples/streamable_http_server.rb
This server has a tool call notification_tool which the clients call
2. Terminal 2: Start Victim Client
python3 legitimate_client.py
3. Terminal 3 - Attacker Client:
Copy the session ID from Terminal 1 and run:
python3 attacker_client.py abc-123-def-456
4. Back to Terminal 2 - Victim sees the injected response:
Impact
- Integrity: HIGH - Attacker can execute unauthorized tools and modify state
- Availability: LOW - Attacker can disrupt victim's session with injected responses
Additional Details
Session Hijacking Protection in MCP Implementations
The MCP specification recommends - "MCP servers SHOULD bind session IDs to user-specific information".
User Binding - Comparison other SDKs
csharp-sdk
- https://github.com/modelcontextprotocol/csharp-sdk/blob/main/
⚡ Watch CVE-2026-67431
Get an email if CVE-2026-67431 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
Advisory coverage (2)
- highGHSA-5p9g-j988-pcwv: MCP Ruby SDK: Ruby SSE Session Poisoningghsa · 2026-07-30
- unknownCVE-2026-67431: MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to…nvd · 2026-07-29
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-67431)