Vulnerability DatabaseGHSA-5p9g-j988-pcwv

GHSA-5p9g-j988-pcwv
Model Context Protocol vulnerability analysis and mitigation

Summary

Vulnerability: Missing Session Ownership Validation in the Ruby MCP SDK's Streamable and SSE HTTP transport implementation. Any attacker with a stolen session ID can execute tools with the victim's session. This is a silent attack - the victim's session is compromised and being used for unauthorized actions, but it is hard to know for the victim

Details

https://github.com/modelcontextprotocol/ruby-sdk/blob/main/lib/mcp/server/transports/streamable_http_transport.rb#L260-L278 Victim starts a legitimate MCP session and receives session ID abc-123 Attacker obtains the session ID (various means - network sniffing, logs, etc. out of scope for this analysis) Attacker sends POST to /messages/abc-123 with a tool call Server accepts the request (no ownership validation!) Server executes the tool and sends response to victim's SSE stream Victim receives attacker's response, thinking it's legitimate

PoC

attacker_client.py legitimate_client.py Prerequisites

  1. Python 3.8+
  2. Install dependencies: requests Running the Demo
  3. Terminal 1: Start the Ruby MCP Server

ruby streamable_http_server.rb Makes use of https://github.com/modelcontextprotocol/ruby-sdk/blob/main/examples/streamable_http_server.rb This server has a tool call notification_tool which the clients call 2. Terminal 2: Start Victim Client python3 legitimate_client.py 3. Terminal 3 - Attacker Client: Copy the session ID from Terminal 1 and run:

python3 attacker_client.py abc-123-def-456
  1. Back to Terminal 2 - Victim sees the injected response:

Impact

  • Integrity: HIGH - Attacker can execute unauthorized tools and modify state
  • Availability: LOW - Attacker can disrupt victim's session with injected responses

Additional Details

Session Hijacking Protection in MCP Implementations The MCP specification recommends - "MCP servers SHOULD bind session IDs to user-specific information".

User Binding - Comparison other SDKs

csharp-sdk

Comparison with the Stream Replacement vulnerability

Stream Replacement https://github.com/modelcontextprotocol/ruby-sdk/security/advisories/GHSA-qvqr-5cv7-wh35

  • Target: SSE stream connection
  • Attack Vector: GET /mcp
  • What happens to Victim: The connection is disconnected and doesn't receive reponses Session Poisoning
  • Target: Tool execution
  • Attack Vector: POST /mcp
  • What happens to Victim: The connection stays connected and receives responses of tool calls by attacker

Wiz Threat Research note: Research is currently evaluating this vulnerability


SourceNVD

Related Model Context Protocol vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-5p9g-j988-pcwvHIGH8.3
  • Model Context Protocol logoModel Context Protocol
  • mcp
NoYesJul 30, 2026
GHSA-h669-8m4g-r2hcHIGH7.5
  • Model Context Protocol logoModel Context Protocol
  • mcp
NoYesJul 30, 2026
GHSA-rjr6-rcgv-9m7mMEDIUM6.9
  • Model Context Protocol logoModel Context Protocol
  • mcp
NoYesJul 30, 2026
GHSA-7683-3w9x-ch42MEDIUM6.2
  • Model Context Protocol logoModel Context Protocol
  • mcp
NoYesJul 30, 2026
GHSA-52jp-gj8w-j6xhMEDIUM5.3
  • Model Context Protocol logoModel Context Protocol
  • mcp
NoYesJul 30, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management