THREAT OPS › Threat News › [GHSA] GHSA-fh3r-g96v-f578 (high) — @arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key
[GHSA] GHSA-fh3r-g96v-f578 (high) — @arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key
GHSA-fh3r-g96v-f578 Severity: high CVE: CVE-2026-55604
@arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key
# Cross-Session Data Exposure via Caller-Controlled `session_id`
Project / Repository: `arikusi/deepseek-mcp-server` Affected version / commit tested: `1.6.0` / `04f28be2c6e99d3d4e443a6ae37cc35f0a71554a` Vulnerability type: Authorization bypass / cross-
Indicators of compromise
- 04f28be2c6e99d3d4e443a6ae37cc35f0a71554asha1
- CVE-2026-55604cve
Original source: https://github.com/advisories/GHSA-fh3r-g96v-f578