A AegiFlow
HIGHCVSS 8.6EPSS 0.4%

CVE-2026-55604

@arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key

Published
2026-08-25
Modified
2026-08-25
EPSS percentile
30%
Aliases
GHSA-fh3r-g96v-f578
Sources
github-advisory

Summary

# Cross-Session Data Exposure via Caller-Controlled `session_id` Project / Repository: `arikusi/deepseek-mcp-server` Affected version / commit tested: `1.6.0` / `04f28be2c6e99d3d4e443a6ae37cc35f0a71554a` Vulnerability type: Authorization bypass / cross-session data exposure Authentication required: No ## Summary The process-global `SessionStore` accepts caller-supplied `session_id` values without binding them to any authenticated principal or transport session. An attacker can enumerate active session IDs via `deepseek_sessions`, then reuse a victim-controlled `session_id` in `deepseek_chat` to retrieve and continue the victim's conversation context. ## Affected Code - `src/session.ts:42` - caller-controlled session IDs are looked up directly from the global in-memory map. - `src/session.ts:67` - a new session is stored under the caller-controlled ID without ownership binding. - `src/session.ts:109` - `getMessages()` retrieves messages for any supplied session ID. - `src/tools/deepseek-chat.ts:195` - `deepseek_chat` creates or reuses the supplied `session_id`. - `src/tools/deepseek-chat.ts:197` - previous messages are loaded from the supplied `session_id`. - `src/tools/deepseek-chat.ts:198` - previous messages are prepended into the attacker-controlled request. - `src/tools/deepseek-chat.ts:243` - attacker-provided user messages are appended into the reused session. - `src/tools/deepseek-chat.ts:245` - assistant responses are appended back into the reused session. - `src/tools/deepseek-sessions.ts:37` - `deepseek_sessions list` enumerates all active sessions. - `src/tools/deepseek-sessions.ts:53` - each enumerated session ID is rendered back to the caller. ## PoC Overview 1. Create a victim conversation with `session_id = "victim-session"`. 2. Call `deepseek_sessions` with `action = "list"` and observe that `victim-session` is disclosed. 3. Call `deepseek_chat` again with `session_id = "victim-session"` from a separate attacker flow. 4. The upstream request now includes the victim's prior messages before the attacker's message. ## Validation Environment Local runtime verification on Windows host with Node.js `v24.11.1`, using the repository code at the tested commit and a local mock DeepSeek client to capture the effective message list passed upstream. ## Impact Any reachable caller can enumerate active session IDs and read prior conversation history stored in memory for other callers within the same server process. The same flaw also allows attacker-controlled continuation of another user's session state. ## Remediation - Bind stored sessions to an authenticated transport session or other server-generated opaque identifier. - Do not allow arbitrary user-supplied `session_id` values to select existing server-side state. - Remove or restrict `deepseek_sessions list` so it does not disclose unrelated session IDs. - Reject reuse of a session unless the caller proves ownership of that session. ## Attached Evidence [01_deepseek-mcp-server_cross_session_data_exposure.txt](https://github.com/user-attachments/files/26991248/01_deepseek-mcp-server_cross_session_data_exposure.txt) --- ## Patches (maintainer) Fixed in **1.7.0**. The HTTP transport's `SessionStore` is no longer a process-wide singleton: each MCP HTTP session gets its own store, injected into the `deepseek_chat` and `deepseek_sessions` tool handlers, so a `session_id` from one HTTP session cannot read, enumerate, or clear another session's state. STDIO transport was never affected (one process per client). Integration tests in `src/transport-isolation.test.ts` assert the isolation. Affected versions `>=1.4.2, <1.7.0` are deprecated on npm. Upgrade to 1.7.0 or later. ## Workaround If upgrading is not immediately possible, run in STDIO transport (unset `TRANSPORT=http`) or stop the HTTP server. ## Credit Reported independently by @232-323 and @2REBCat (tested against 1.6.0). The same root cause was found and fixed concurrently by the maintainer during a

Affected packages

EcosystemPackageAffected versionsFixed versions
npm@arikusi/deepseek-mcp-server1.7.0

Remediation: Upgrade to 1.7.0 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.