HIGHRubyGems

MCP Ruby SDK: Ruby SSE Session Poisoning

MCP Ruby SDK: Ruby SSE Session Poisoning

CVE-2026-67431Published 3 weeks agoUpdated 3 weeks agoSource: OSV

Affected packages

  • mcpbefore 0.23.0

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
0.28%
EPSS percentile
19.8%

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 20%.

MCP Ruby SDK: Ruby SSE Session Poisoning | HackTribune