vulnerability · DiggingBeagle record
CVE-2026-59950
Host/Origin validation gap in the MCP Python SDK deprecated WebSocket server transport.
- Entity kind
- vulnerability
A relationship records context, not guilt, vulnerability or endorsement.
Record description
Affected versions before 1.28.1; patched in 1.28.1.
Cite this record
DiggingBeagle. “CVE-2026-59950.” https://diggingbeagle.com/entities/cve-2026-59950/
Citation guidance