{"id":"PYSEC-2026-3481","summary":"MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks","details":"### Summary\nIn affected versions, the default request handlers installed by the experimental tasks feature (`server.experimental.enable_tasks()`) did not check which session created a task before acting on it. On a server with more than one connected client, any client could observe, read results from, and cancel tasks belonging to other clients.\n\n### Am I affected?\nOnly if the developer's application server calls `server.experimental.enable_tasks()`. If `grep -r enable_tasks` over their codebase finds nothing, the application is not affected.\n\n### Details\nWhen tasks support is enabled on the low-level server, default handlers are registered for `tasks/list`, `tasks/get`, `tasks/result`, and `tasks/cancel`. These handlers operated on the task identifier alone and kept no record of the session that created each task. Because `tasks/list` returned every task in the store, a connected client did not need to know any identifiers in advance: it could enumerate all tasks, read any task's status and result via `tasks/get` and `tasks/result`, retrieve queued task messages — such as elicitation requests intended for the task's creator, which are removed from the queue on delivery, so the intended recipient never receives them — and cancel any task via `tasks/cancel`.\n\n### Impact\nServers that call `server.experimental.enable_tasks()` and serve multiple clients are affected: one client can read other clients' task results and elicitation payloads, consume messages meant for them, and cancel their tasks. The feature is experimental and opt-in, so servers that never enable it are unaffected. Servers that registered their own task handlers instead of the defaults are affected only if those handlers have the same omission.\n\n### Mitigation\nUpgrade to version 1.27.2 or later, in which task IDs generated by `run_task()` embed an opaque per-session marker and the default handlers restrict each session to its own tasks: requests for another session's task receive \"task not found\", and `tasks/list` returns only the requesting session's tasks. Tasks created with explicitly chosen IDs or written directly through a `TaskStore` remain reachable by ID but are not listed. Alternatively, leave the experimental tasks feature disabled, or register task handlers that validate session ownership.","aliases":["CVE-2026-52870","GHSA-hvrp-rf83-w775"],"modified":"2026-07-23T15:00:13.878977054Z","published":"2026-07-23T11:41:46.409906Z","references":[{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/security/advisories/GHSA-hvrp-rf83-w775"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-52870"},{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/pull/2720"},{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/commit/62137874ff26dd74d2fea80ff528a7fd9ca7a5e7"},{"type":"PACKAGE","url":"https://github.com/modelcontextprotocol/python-sdk"},{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/releases/tag/v1.27.2"},{"type":"PACKAGE","url":"https://pypi.org/project/mcp"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-hvrp-rf83-w775"}],"affected":[{"package":{"name":"mcp","ecosystem":"PyPI","purl":"pkg:pypi/mcp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.23.0"},{"fixed":"1.27.2"}]}],"versions":["1.23.0","1.23.1","1.23.2","1.23.3","1.24.0","1.25.0","1.26.0","1.27.0","1.27.1"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/mcp/PYSEC-2026-3481.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L"}]}