Junglewise Threat Intelligence

CVE-2026-33946: MCP Ruby SDK: Insufficient Session Binding Allows SSE Stream Hijacking via Session ID Replay

CVE-2026-33946 · Severity: medium · CVSS 4 · Published 2026-03-27

Vendors: RubyGems.

Executive brief

MCP Ruby SDK: Insufficient Session Binding Allows SSE Stream Hijacking via Session ID Replay

Affected products

  • RubyGems mcp

Related threats