THREAT OPS › Threat News › [GHSA] GHSA-5p9g-j988-pcwv (high) — MCP Ruby SDK: Ruby SSE Session Poisoning
[GHSA] GHSA-5p9g-j988-pcwv (high) — MCP Ruby SDK: Ruby SSE Session Poisoning
GHSA-5p9g-j988-pcwv Severity: high CVE: CVE-2026-67431
MCP Ruby SDK: Ruby SSE Session Poisoning
### Summary **Vulnerability**: Missing Session Ownership Validation in the Ruby MCP SDK's Streamable and SSE HTTP transport implementation. Any attacker with a stolen session ID can execute tools with the victim's session. This is a silent attack - the victim's session is compromised and being used fo
Indicators of compromise
- CVE-2026-67431cve
- https://modelcontextprotocol.io/docs/tutorials/security/security_best_practices#mitigation-4url
Original source: https://github.com/advisories/GHSA-5p9g-j988-pcwv