CVE-2026-33946: MCP Ruby SDK: Insufficient Session Binding Allows SSE Stream Hijacking via Session ID Replay

Published Mar 27, 2026
·
Updated

Summary

The Ruby SDK's streamablehttptransport.rb implementation contains a session hijacking vulnerability. An attacker who obtains a valid session ID can completely hijack the victim's Server-Sent Events (SSE) stream and intercept all real-time data.

Details Root Cause The StreamableHTTPTransport implementation stores only one SSE stream object per session ID and lacks:

- Session-to-user identity binding - Ownership validation when establishing SSE connections - Protection against multiple simultaneous connections to the same session

PoC

Vulnerable Code

File: streamablehttptransport.rb - L336-L339:

def storestreamforsession(sessionid, stream) @mutex.synchronize do if @sessions[sessionid] @sessions[sessionid][:stream] = stream # OVERWRITES existing stream else stream.close end end end Attack Scenario Step 1: Legitimate Session Establishment POST / (initialize) → receives sessionid: "abc123" GET / with Mcp-Session-Id: abc123 → SSE stream connected Step 2: Session ID Compromise

- An attacker obtains the session ID through various means (out of scope for this analysis)

Step 3: Stream Hijacking

GET / with Mcp-Session-Id: abc123 @sessions["abc123"][:stream] = attackerstream # Victim's stream is REPLACED (silently disconnected)

Step 4: Data Interception

- ALL subsequent tool responses/notifications go to the attacker - The legitimate user receives no data and has no indication of the hijacking

Technical Details

The vulnerability happens:

Client 1 connects (GET request)

proc do |stream1| # ← Rack server provides stream1 for client 1 @sessions[sessionid][:stream] = stream1 # Stored end

Client 2 connects with SAME session ID (Attack!) proc do |stream2| # ← Rack provides stream2 for client 2 @sessions[sessionid][:stream] = stream2 # REPLACES stream1! end

Now when the server sends notifications:

@sessions[sessionid][:stream].write(data) # Goes to stream2 (attacker!) stream1 (victim) receives nothing

Comparison: Python SDK Protection

The Python SDK prevents this vulnerability by rejecting duplicate SSE connections:

Refer: https://github.com/modelcontextprotocol/python-sdk/blob/main/src/mcp/server/streamablehttp.py#L680-L685

if GETSTREAMKEY in self.requeststreams: # pragma: no cover response = self.createerrorresponse( "Conflict: Only one SSE stream is allowed per session", HTTPStatus.CONFLICT, )

When a duplicate connection attempt is detected, the Python SDK returns an HTTP 409 Conflict error, protecting the existing connection.

Recommended Mitigations For SDK Maintainers

- Implement User Binding: All SDKs should bind session IDs to authenticated user identities where possible. Currently only, go-sdk and csharp-sdk do user binding. - Ruby SDK: Prevent Duplicate Connections: Implement checks to reject or handle multiple simultaneous connections to the same session - Improve Documentation: Provide clear guidance on secure session management implementation for SDK consumers

Steps To Reproduce:

Please find attached two python client files demonstrating the attack

Terminal 1: ruby streamablehttpserver.rb

Makes use of https://github.com/modelcontextprotocol/ruby-sdk/blob/main/examples/streamablehttpserver.rb This server has a tool call notificationtool which the clients call

Terminal 2:

python3 legitimateclientrubyserver.py

What happens:

- The client connects and prints the session ID - Press Enter to start the SSE stream - Notifications start appearing every 3 seconds as the client makes a tool call

Terminal 3 (while the legitimate client is running):

python3 attackerclientrubyserver.py <SESSIONID>

Replace <SESSIONID> with the ID from Terminal 2.

What happens immediately:

- Terminal 2 (Legitimate): Stops receiving notifications, shows disconnect message - Terminal 3 (Attacker): Starts receiving ALL the tool call responses

Impact While the absence of user binding may not pose immediate risks if session IDs are not used to store sensitive data or state, the fundamental purpose of session IDs is to maintain stateful connections. If the SDK or its consumers utilize session IDs for sensitive operations without proper user binding controls, this creates a potential security vulnerability. For example: In the case of the Ruby SDK, the attacker was able to hijack the stream and receive all the tool responses belonging to the victim. The tool responses can be sensitive confidential data.

Additional Details Session Hijacking Protection in MCP Implementations The MCP specification recommends - "MCP servers SHOULD bind session IDs to user-specific information".

Current Implementation Status Across SDKs

Of the 10 official MCP SDKs, only the following implementations bind session IDs to user-specific information:

1. csharp-sdk - https://github.com/modelcontextprotocol/csharp-sdk/blob/main/src/ModelContextProtocol.AspNetCore/SseHandler.cs#L93-L97 2. Go-sdk - https://github.com/modelcontextprotocol/go-sdk/blob/main/mcp/streamable.go#L281C1-L288C2

attackerclientrubyserver.py legitimateclientrubyserver.py The remaining SDKs do not implement session-to-user binding. Most implementations only verify that a session ID exists, without validating ownership. Additionally, SDK documentation does not provide clear guidance on implementing secure session management, leaving security responsibilities unclear for SDK consumers.

Other sources

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to version 0.9.2, the Ruby SDK's streamablehttptransport.rb implementation contains a session hijacking vulnerability. An attacker who obtains a valid session ID can completely hijack the victim's Server-Sent Events (SSE) stream and intercept all real-time data. Version 0.9.2 contains a patch.

MITRE

Affected Software

2 affected componentsFixes available
rubygems/mcp<=0.9.1
0.9.2
Lfprojects Mcp Ruby Sdk<0.9.2

Event History

Mar 27, 2026
Advisory Published
via GitHub·06:36 PM
Data Sourced
via GitHub·06:36 PM
DescriptionWeaknessAffected Software
CVE Published
via MITRE·09:20 PM
Data Sourced
via MITRE·09:20 PM
DescriptionWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
RemedyAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-33946?

CVE-2026-33946 is considered a critical vulnerability due to its ability to allow session hijacking.

2

How do I fix CVE-2026-33946?

To fix CVE-2026-33946, upgrade the Ruby SDK 'mcp' package to version 0.9.2 or later.

3

Who is affected by CVE-2026-33946?

CVE-2026-33946 affects users of the 'mcp' Ruby SDK version 0.9.1 and below.

4

What type of vulnerability is CVE-2026-33946?

CVE-2026-33946 is classified as a session hijacking vulnerability.

5

Can CVE-2026-33946 lead to data breaches?

Yes, CVE-2026-33946 can potentially lead to data breaches by allowing attackers to gain unauthorized access to user sessions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203