Junglewise Threat Intelligence

CVE-2026-55604: arikusi deepseek-mcp-server authorization bypass in SessionStore

CVE-2026-55604 · Severity: high · CVSS 8.6 · Published 2026-07-09

Vendors: npm.

Executive brief

The deepseek-mcp-server library uses in-memory conversation sessions that are stored in a process-wide store without binding them to individual users or transport connections. An attacker with network access can enumerate all active conversation sessions and hijack any victim's session to read their conversation history, inject new messages, or delete their sessions. This affects any deployment using the HTTP transport mode.

Technical details

The SessionStore component accepts caller-supplied session_id values without verifying ownership or binding them to an authenticated principal or transport session. An attacker can call deepseek_sessions with action="list" to enumerate all active session IDs, then reuse a victim's session_id in subsequent deepseek_chat calls to access prior messages (CWE-639). The vulnerable code accepts user-controlled session IDs directly from the global in-memory map (src/session.ts:42, :67, :109) and does not perform ownership validation. Attack vectors include reading other users' conversation history, injecting malicious messages into their sessions, and clearing sessions. Authentication is not required. The fix in 1.7.0 moves SessionStore from a process-wide singleton to per-HTTP-session isolation, preventing cross-session leakage. Affected versions >=1.4.2, <1.7.0 should be upgraded immediately; STDIO transport was never affected.

Affected products

  • arikusi deepseek-mcp-server >=1.4.2, <1.7.0

Timeline

  • 2026-06-14: disclosed: Vulnerability reviewed and published by GitHub Advisory Database
  • 2026-06-14: patched: Fixed in version 1.7.0
  • 2026-08-25: advisory: Advisory updated and finalized

References

Related threats