HIGH 8.6 GitHub
CVE-2026-55604
@arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key
# Cross-Session Data Exposure via Caller-Controlled `session_id`
Project / Repository: `arikusi/deepseek-mcp-server`
Affected version / commit tested: `1.6.0` / `04f28be2c6e99d3d4e443a6ae37cc35f0a71554a`
Vulnerability type: Authorization bypass / cross-session data exposure
Authentication required: No
## Summary
The process-global `SessionStore` accepts caller-supplied `session_id` values without binding them to any authenticated principal or transport session. An attacker can enumerate a
Affected Products
- npm/@arikusi/deepseek-mcp-server >= 1.4.2, < 1.7.0
References
- https://github.com/advisories/GHSA-fh3r-g96v-f578
- https://github.com/arikusi/deepseek-mcp-server/security/advisories/GHSA-fh3r-g96v-f578
- https://nvd.nist.gov/vuln/detail/CVE-2026-55604
- https://github.com/arikusi/deepseek-mcp-server/releases/tag/v1.7.0
This high severity vulnerability with a CVSS score of 8.6 was published on 2026-08-25 via GitHub. Affected: npm/@arikusi/deepseek-mcp-server >= 1.4.2, < 1.7.0.
vulnfeed aggregates 11950 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.