THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-fh3r-g96v-f578 (high) — @arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key

[GHSA] GHSA-fh3r-g96v-f578 (high) — @arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key

highgithub_advisoriesPublished 2026-08-25

GHSA-fh3r-g96v-f578 Severity: high CVE: CVE-2026-55604

@arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key

# Cross-Session Data Exposure via Caller-Controlled `session_id`

Project / Repository: `arikusi/deepseek-mcp-server` Affected version / commit tested: `1.6.0` / `04f28be2c6e99d3d4e443a6ae37cc35f0a71554a` Vulnerability type: Authorization bypass / cross-

Indicators of compromise

Original source: https://github.com/advisories/GHSA-fh3r-g96v-f578