CVE-2026-33946 identifies a high-severity session hijacking vulnerability in the MCP Ruby SDK, affecting versions prior to 0.9.2. This flaw in the streamable_http_transport.rb implementation allows an attacker who obtains a valid session ID to completely hijack a victim's Server-Sent Events (SSE) stream and intercept all real-time data. Rated 8.2 HIGH on CVSS, the vulnerability can be exploited remotely over the network with low attack complexity, requiring no user interaction or privileges. There is currently no evidence of active exploitation, public exploit code, or media coverage, though it has received some community discussion. Organizations using the affected SDK should upgrade to version 0.9.2, which includes a patch.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.9.2CPE matchmatch criteria | cpe:2.3:a:lfprojects:mcp_ruby_sdk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.