Session ID Binding Issue in MCP Ruby SDK by Model Context Protocol
CVE-2026-67431
8.3HIGH
What is CVE-2026-67431?
The MCP Ruby SDK, used for Model Context Protocol servers and clients, suffers from a session ID binding vulnerability. This flaw allows an attacker to exploit a stolen session ID, leading to unauthorized execution of tool calls within the context of the affected user’s session. This issue has been addressed in version 0.23.0, which ensures that a session ID is correctly bound to a session owner, thereby mitigating the risk of session hijacking. To protect your data, it is highly recommended to upgrade to this version or later.
Affected Version(s)
ruby-sdk < 0.23.0
