Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.6
CVE-2026-59950: MCP Python SDK accepts any WebSocket origin
CVE-2026-59950 · published 2 months ago
Summary
The MCP Python SDK's WebSocket server component did not check the Host or Origin headers, so any website could connect to services using it. This could let unauthorized parties interact with your application. Upgrade to version 1.28.1 or later, which adds the missing checks, or stop using the deprecated WebSocket transport.
What to do
- Update rootio-mcp to version 1.27.0+root.io.1.
- Update model context protocol a series of lf projects mcp to version 1.28.1.
- Update lfprojects mcp_python_sdk to version 1.28.1 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | modelcontextprotocol | python-sdk | < 1.28.1 |
| – | lfprojects | mcp_python_sdk |
< 1.28.1 cpe:2.3:a:lfprojects:mcp_python_sdk:*:*:*:*:*:*:*:* |
| Root:PyPI | – | rootio-mcp |
< 1.27.0+root.io.1 Fix: upgrade to 1.27.0+root.io.1
|
| pip | model context protocol a series of lf projects | mcp |
< 1.28.1 Fix: upgrade to 1.28.1
|
Original advisory text
MCP Python SDK: WebSocket server transport does not support Host/Origin validation
The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_server transport accepted WebSocket handshakes without applying Host or Origin header validation, leaving no SDK-level way to restrict which origins could connect to applications that exposed that transport. This issue is fixed in version 1.28.1.
References
- https://github.com/modelcontextprotocol/python-sdk/security/advisories/GHSA-vj7q... Vendor Advisory
- https://github.com/modelcontextprotocol/python-sdk/pull/2992 Issue Tracking Patch
- https://github.com/modelcontextprotocol/python-sdk/commit/777b8d06710c140e3606b0... Patch
- https://github.com/modelcontextprotocol/python-sdk/releases/tag/v1.28.1 Release Notes
- https://nvd.nist.gov/vuln/detail/CVE-2026-59950
- https://github.com/advisories/GHSA-vj7q-gjh5-988w
- https://github.com/modelcontextprotocol/python-sdk Product
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59950... Vendor Advisory
- https://pypi.org/project/mcp Product
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
7.6
High
Type
CWE-346Origin Validation Error
CWE-1385Missing Origin Validation in WebSockets
Timeline
Published15 Jul 2026
Updated3 Oct 2026
First seen15 Jul 2026
Sources
CVE-2026-59950 · NVD
CVE-2026-59950 · MITRE
GHSA-vj7q-gjh5-988w · GHSA
GHSA-vj7q-gjh5-988w · OSV
CVE-2026-59950 · OSV
PYSEC-2026-3483 · OSV
Track software like this
Free during beta