Source · DiggingBeagle record

MCP Python SDK experimental task handlers allowed cross-client task access

GitHub security advisory for CVE-2026-52870, affecting opt-in experimental tasks in mcp 1.23.0 through 1.27.1 and fixed in 1.27.2.

Published
Jun 5, 2026
Accessed
Sep 15, 2026
Publisher
Model Context Protocol Python SDK / GitHub Security Advisory
Source type
primary
Version
2026-06-05
Rights
Public web source; citation and short excerpt/paraphrase only.

Each support, contradiction or context label applies to a cited Claim, not to a whole Case.

Cite this record

DiggingBeagle. “MCP Python SDK experimental task handlers allowed cross-client task access.” Published Jun 5, 2026 · Accessed Sep 15, 2026. https://diggingbeagle.com/sources/mcp-python-sdk-experimental-task-handlers-allowed-cross-client-task-access/

Citation guidance

Why this archive exists

The source matters after the headline fades.

DiggingBeagle is a non profit research project documenting AI security incidents, agent failures, vulnerabilities and AI-assisted operations. A case keeps its claims beside the sources that support, contest or limit them. Later updates stay visible, so a reader can see when the account changed.

We publish case reconstructions, dated reporting and analysis across records. Each has a different evidentiary role. About the project and our methodology explain how the work is reviewed.