Skip to content

Fix for GHSA-jpw9-pfvf-9f58#198

Closed
keycard-gh-workflows-access[bot] wants to merge 1 commit into
mainfrom
socket/fix/GHSA-jpw9-pfvf-9f58
Closed

Fix for GHSA-jpw9-pfvf-9f58#198
keycard-gh-workflows-access[bot] wants to merge 1 commit into
mainfrom
socket/fix/GHSA-jpw9-pfvf-9f58

Conversation

@keycard-gh-workflows-access

Copy link
Copy Markdown
Contributor

Socket fix for GHSA-jpw9-pfvf-9f58.

Vulnerability Summary: MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal

Severity: HIGH

Affected Packages: mcp (PIP)

…ion requests without verifying the authenticated principal
@keycard-gh-workflows-access
keycard-gh-workflows-access Bot enabled auto-merge (squash) July 20, 2026 07:23
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedpypi/​mcp@​1.27.0 ⏵ 1.27.299 +185 +15100100100

View full report

auto-merge was automatically disabled July 20, 2026 18:16

Pull request was closed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant