THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-5p9g-j988-pcwv (high) — MCP Ruby SDK: Ruby SSE Session Poisoning

[GHSA] GHSA-5p9g-j988-pcwv (high) — MCP Ruby SDK: Ruby SSE Session Poisoning

highgithub_advisoriesPublished 2026-07-30

GHSA-5p9g-j988-pcwv Severity: high CVE: CVE-2026-67431

MCP Ruby SDK: Ruby SSE Session Poisoning

### Summary **Vulnerability**: Missing Session Ownership Validation in the Ruby MCP SDK's Streamable and SSE HTTP transport implementation. Any attacker with a stolen session ID can execute tools with the victim's session. This is a silent attack - the victim's session is compromised and being used fo

Indicators of compromise

Original source: https://github.com/advisories/GHSA-5p9g-j988-pcwv