CVE-2026-52870
Last modified
CVE-2026-52870 is a high-severity vulnerability rated 7.6/10 on the CVSS scale. The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed by server.experimental.enable_tasks() for tasks/list, tasks/get, tasks/result, and tasks/cancel operate only on task identifiers without recording the session that created each task, allowing any connected client to enumerate, read results from, consume messages for, or cancel other clients' tasks. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed by server.experimental.enable_tasks() for tasks/list, tasks/get, tasks/result, and tasks/cancel operate only on task identifiers without recording the session that created each task, allowing any connected client to enumerate, read results from, consume messages for, or cancel other clients' tasks. This issue is fixed in version 1.27.2.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lfprojects | Mcp Python Sdk | >= 1.23.0, < 1.27.2 |
References
- https://github.com/modelcontextprotocol/python-sdk/pull/2720Issue Tracking, Patch
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-52870?
How severe is CVE-2026-52870?
How do I fix CVE-2026-52870?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-52863In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a f…5.9
- CVE-2026-52865When NGINX Ingress Controller processes Ingress or Transport…7.1
- CVE-2026-52866An attacker within BLE communication range can monopolize th…7.1
- CVE-2026-52868An unauthenticated attacker can read worklist records from a…8.8
- CVE-2026-52869The MCP Python SDK, called mcp on PyPI, is a Python implemen…7.1
- CVE-2026-5287Use after free in PDF in Google Chrome prior to 146.0.7680.1…8.8
- CVE-2026-52878Klever-Go is the Go implementation of the Klever blockchain …7.5
- CVE-2026-52879Klever-Go is the Go implementation of the Klever blockchain …7.5
- CVE-2026-5288Use after free in WebView in Google Chrome on Android prior …9.6
- CVE-2026-52880Klever-Go is the Go implementation of the Klever blockchain …7.5
- CVE-2026-52884Notepad++ is a free and open-source source code editor. In v…7.8
- CVE-2026-52885Notepad++ is a free and open-source source code editor. Prio…6.3
Are you affected by CVE-2026-52870?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
