Executive brief
MCP Ruby SDK: Insufficient Session Binding Allows SSE Stream Hijacking via Session ID Replay
Affected products
- RubyGems mcp
Junglewise Threat Intelligence
CVE-2026-33946 · Severity: medium · CVSS 4 · Published 2026-03-27
Vendors: RubyGems.
MCP Ruby SDK: Insufficient Session Binding Allows SSE Stream Hijacking via Session ID Replay