CVE-2025-6515 describes a vulnerability in the oatpp-mcp SSE endpoint where an instance pointer is used as a session ID, making it predictable and insecure. This allows network attackers to guess future session IDs and hijack legitimate client MCP sessions, leading to malicious responses from the server. The vulnerability has a CVSS score of 6.8 (Medium) due to its network attack vector, high attack complexity, and high impact on integrity and availability, though it requires user interaction. There is no known active exploitation, public exploit code, or KEV listing, but it has garnered some community discussion and media coverage, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Oatpp | Oatpp-Mcp | 0CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.