The MCP SSE endpoint in oatpp-mcp returns an instance...
Moderate severity
Unreviewed
Published
Oct 20, 2025
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Oct 20, 2025
Published to the GitHub Advisory Database
Oct 20, 2025
The MCP SSE endpoint in oatpp-mcp returns an instance pointer as the session ID, which is not unique nor cryptographically secure. This allows network attackers with access to the oatpp-mcp server to guess future session IDs and hijack legitimate client MCP sessions, returning malicious responses from the oatpp-mcp server.
References