CVE-2026-55604: @arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key
The process-global SessionStore accepts caller-supplied session_id values without binding them to any authenticated principal or transport session. An attacker can enumerate active session IDs via deepseek_sessions, then reuse a victim-controlled session_id in deepseek_chat to retrieve and continue the victim’s conversation context.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-55604 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →