CVE-2026-33946

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
27/03/2026
Last modified:
02/04/2026

Description

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to version 0.9.2, the Ruby SDK's streamable_http_transport.rb implementation contains a session hijacking vulnerability. An attacker who obtains a valid session ID can completely hijack the victim's Server-Sent Events (SSE) stream and intercept all real-time data. Version 0.9.2 contains a patch.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lfprojects:mcp_ruby_sdk:*:*:*:*:*:*:*:* 0.9.2 (excluding)