CVE-2026-55604High· 8.6▾ Twilight@arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 47.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.4%
session_idProject / Repository: arikusi/deepseek-mcp-server
Affected version / commit tested: 1.6.0 / 04f28be2c6e99d3d4e443a6ae37cc35f0a71554a
Vulnerability type: Authorization bypass / cross-session data exposure
Authentication required: No
The process-global SessionStore accepts caller-supplied session_id values without binding them to any authenticated principal or transport session. An attacker can enumerate active session IDs via deepseek_sessions, then reuse a victim-controlled session_id in deepseek_chat to retrieve and continue the victim's conversation context.
src/session.ts:42 - caller-controlled session IDs are looked up directly from the global in-memory map.src/session.ts:67 - a new session is stored under the caller-controlled ID without ownership binding.src/session.ts:109 - getMessages() retrieves messages for any supplied session ID.src/tools/deepseek-chat.ts:195 - deepseek_chat creates or reuses the supplied session_id.src/tools/deepseek-chat.ts:197 - previous messages are loaded from the supplied session_id.src/tools/deepseek-chat.ts:198 - previous messages are prepended into the attacker-controlled request.src/tools/deepseek-chat.ts:243 - attacker-provided user messages are appended into the reused session.src/tools/deepseek-chat.ts:245 - assistant responses are appended back into the reused session.src/tools/deepseek-sessions.ts:37 - deepseek_sessions list enumerates all active sessions.src/tools/deepseek-sessions.ts:53 - each enumerated session ID is rendered back to the caller.session_id = "victim-session".deepseek_sessions with action = "list" and observe that victim-session is disclosed.deepseek_chat again with session_id = "victim-session" from a separate attacker flow.Local runtime verification on Windows host with Node.js v24.11.1, using the repository code at the tested commit and a local mock DeepSeek client to capture the effective message list passed upstream.
Any reachable caller can enumerate active session IDs and read prior conversation history stored in memory for other callers within the same server process. The same flaw also allows attacker-controlled continuation of another user's session state.
session_id values to select existing server-side state.deepseek_sessions list so it does not disclose unrelated session IDs.01_deepseek-mcp-server_cross_session_data_exposure.txt
Fixed in 1.7.0. The HTTP transport's SessionStore is no longer a process-wide singleton: each MCP HTTP session gets its own store, injected into the deepseek_chat and deepseek_sessions tool handlers, so a session_id from one HTTP session cannot read, enumerate, or clear another session's state. STDIO transport was never affected (one process per client). Integration tests in src/transport-isolation.test.ts assert the isolation.
Affected versions >=1.4.2, <1.7.0 are deprecated on npm. Upgrade to 1.7.0 or later.
If upgrading is not immediately possible, run in STDIO transport (unset TRANSPORT=http) or stop the HTTP server.
Reported independently by @232-323 and @2REBCat (tested against 1.6.0). The same root cause was found and fixed concurrently by the maintainer during a security audit, shipped in 1.7.0. All parties are credited as finders.
A connected client could read other clients' conversation history (C:H), inject messages into their sessions (I:L), and clear or delete other clients' sessions (A:L). Scope is unchanged: the impact stays within the application's own authorization boundary, which is a cross-tenant authorization bypass, so S:U is correct.
@arikusi/deepseek-mcp-server >= 1.4.2, < 1.7.0Upgrade to a patched release:
@arikusi/deepseek-mcp-server 1.7.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55605Medium· 5.3@arikusi/deepseek-mcp-server: Missing Authentication on Self-Hosted HTTP MCP Endpoint
CVE-2021-46416High· 8.1Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.
CVE-2025-14459High· 8.5A flaw was found in KubeVirt Containerized Data Importer (CDI)
CVE-2026-20897Critical· 9.1Gitea does not properly validate repository ownership when deleting Git LFS locks
CVE-2026-55178High· 7.5GeoLens is a self-hosted geospatial data catalog with semantic search, OGC and STAC APIs, and a map builder
CVE-2026-54052Critical· 9.9n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments