Source · DiggingBeagle record

MCP Python SDK deprecated WebSocket transport lacked Host and Origin validation

GitHub security advisory for CVE-2026-59950, affecting the deprecated MCP Python SDK WebSocket server transport before 1.28.1.

Published
Jul 7, 2026
Accessed
Sep 15, 2026
Publisher
Model Context Protocol Python SDK / GitHub Security Advisory
Source type
primary
Version
2026-07-07
Rights
Public web source; citation and short excerpt/paraphrase only.

Each support, contradiction or context label applies to a cited Claim, not to a whole Case.

Cite this record

DiggingBeagle. “MCP Python SDK deprecated WebSocket transport lacked Host and Origin validation.” Published Jul 7, 2026 · Accessed Sep 15, 2026. https://diggingbeagle.com/sources/mcp-python-sdk-deprecated-websocket-transport-lacked-host-and-origin-validation/

Citation guidance

Why this archive exists

The source matters after the headline fades.

DiggingBeagle is a non profit research project documenting AI security incidents, agent failures, vulnerabilities and AI-assisted operations. A case keeps its claims beside the sources that support, contest or limit them. Later updates stay visible, so a reader can see when the account changed.

We publish case reconstructions, dated reporting and analysis across records. Each has a different evidentiary role. About the project and our methodology explain how the work is reviewed.