HIGH 8.6 GitHub

CVE-2026-55604

@arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key

# Cross-Session Data Exposure via Caller-Controlled `session_id` Project / Repository: `arikusi/deepseek-mcp-server` Affected version / commit tested: `1.6.0` / `04f28be2c6e99d3d4e443a6ae37cc35f0a71554a` Vulnerability type: Authorization bypass / cross-session data exposure Authentication required: No ## Summary The process-global `SessionStore` accepts caller-supplied `session_id` values without binding them to any authenticated principal or transport session. An attacker can enumerate a

Affected Products

References

Published: 2026-08-25 · Source: GitHub · Feed updated: 2026-08-25
This high severity vulnerability with a CVSS score of 8.6 was published on 2026-08-25 via GitHub. Affected: npm/@arikusi/deepseek-mcp-server >= 1.4.2, < 1.7.0.
vulnfeed aggregates 11950 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.