Popis
The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed by server.experimental.enable_tasks() for tasks/list, tasks/get, tasks/result, and tasks/cancel operate only on task identifiers without recording the session that created each task, allowing any connected client to enumerate, read results from, consume messages for, or cancel other clients- tasks. This issue is fixed in version 1.27.2.
CVSS 7.6EPSS 0.23600000000000002%Riziko 0.78
Zobraziť zdroj- Zverejnené
- 2026-07-15 20:17:38
- Dotknuté verzie
- >=1.23.0, <1.27.2
- Typ
- Knižnica
- Vektor
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L