Source · DiggingBeagle record
MCP Python SDK experimental task handlers allowed cross-client task access
GitHub security advisory for CVE-2026-52870, affecting opt-in experimental tasks in mcp 1.23.0 through 1.27.1 and fixed in 1.27.2.
- Published
- Jun 5, 2026
- Accessed
- Sep 15, 2026
- Publisher
- Model Context Protocol Python SDK / GitHub Security Advisory
- Source type
- primary
- Version
- 2026-06-05
- Rights
- Public web source; citation and short excerpt/paraphrase only.
Each support, contradiction or context label applies to a cited Claim, not to a whole Case.
Source record
Default experimental task handlers acted on task identifiers without binding them to the creating session, allowing other connected clients to observe, retrieve or cancel those tasks.
Claim-level citations (3)
- supportsMCP Python SDK tasks crossed client-session boundaries: The default experimental task handlers did not bind a task to the session that created it, so another connected client could observe, read results from or cancel that task.
Summary and details
- supportsMCP Python SDK tasks crossed client-session boundaries: The MCP Python SDK advisory lists version 1.27.2 as the patched version for CVE-2026-52870.
Patched versions
- supportsMCP Python SDK tasks crossed client-session boundaries: CVE-2026-52870 affected MCP Python SDK versions 1.23.0 through 1.27.1 when applications explicitly enabled the experimental tasks feature.
Affected versions and Am I affected?
Cite this record
DiggingBeagle. “MCP Python SDK experimental task handlers allowed cross-client task access.” Published Jun 5, 2026 · Accessed Sep 15, 2026. https://diggingbeagle.com/sources/mcp-python-sdk-experimental-task-handlers-allowed-cross-client-task-access/
Citation guidance