MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks
High7.6CVE-2026-52870 · Published Jul 16, 2026 · updated Sep 10, 2026
### Summary In affected versions, the default request handlers installed by the experimental tasks feature (`server.experimental.enable_tasks()`) did not check which session created a task before acting on it. On a server with more than one connected client, any client could observe, read results from, and cancel tasks belonging to other clients. ### Am I affected? Only if the developer's application server calls `server.experimental.enable_tasks()`. If `grep -r enable_tasks` over their codebase finds nothing, the application is not affected. ### Details When tasks support is enabled on the low-level server, default handlers are registered for `tasks/list`, `tasks/get`, `tasks/result`, and `tasks/cancel`. These handlers operated on the task identifier alone and kept no record of the session that created each task. Because `tasks/list` returned every task in the store, a connected client did not need to know any identifiers in advance: it could enumerate all tasks, read any task's status and result via `tasks/get` and `tasks/result`, retrieve queued task messages , such as elicitation requests intended for the task's creator, which are removed from the queue on delivery, so the i...
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| mcp PyPI | >= 1.23.0, < 1.27.2 | 1.27.2 |
Details and references
### Summary In affected versions, the default request handlers installed by the experimental tasks feature (`server.experimental.enable_tasks()`) did not check which session created a task before acting on it. On a server with more than one connected client, any client could observe, read results from, and cancel tasks belonging to other clients. ### Am I affected? Only if the developer's application server calls `server.experimental.enable_tasks()`. If `grep -r enable_tasks` over their codebase finds nothing, the application is not affected. ### Details When tasks support is enabled on the low-level server, default handlers are registered for `tasks/list`, `tasks/get`, `tasks/result`, and `tasks/cancel`. These handlers operated on the task identifier alone and kept no record of the session that created each task. Because `tasks/list` returned every task in the store, a connected client did not need to know any identifiers in advance: it could enumerate all tasks, read any task's status and result via `tasks/get` and `tasks/result`, retrieve queued task messages , such as elicitation requests intended for the task's creator, which are removed from the queue on delivery, so the intended recipient never receives them , and cancel any task via `tasks/cancel`. ### Impact Servers that call `server.experimental.enable_tasks()` and serve multiple clients are affected: one client can read other clients' task results and elicitation payloads, consume messages meant for them, and cancel their tasks. The feature is experimental and opt-in, so servers that never enable it are unaffected. Servers that registered their own task handlers instead of the defaults are affected only if those handlers have the same omission. ### Mitigation Upgrade to version 1.27.2 or later, in which task IDs generated by `run_task()` embed an opaque per-session marker and the default handlers restrict each session to its own tasks: requests for another session's task receive "task not found", and `tasks/list` returns only the requesting session's tasks. Tasks created with explicitly chosen IDs or written directly through a `TaskStore` remain reachable by ID but are not listed. Alternatively, leave the experimental tasks feature disabled, or register task handlers that validate session ownership.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-862
- Also known as
- CVE-2026-52870, PYSEC-2026-3481
- github.com/modelcontextprotocol/python-sdk/security/advisories/GHSA-hvrp-rf83-w775
- nvd.nist.gov/vuln/detail/CVE-2026-52870
- github.com/modelcontextprotocol/python-sdk/pull/2720
- github.com/modelcontextprotocol/python-sdk/commit/62137874ff26dd74d2fea80ff528a7fd9ca7a5e7
- github.com/modelcontextprotocol/python-sdk
- github.com/modelcontextprotocol/python-sdk/releases/tag/v1.27.2
More MCP SDKs advisories
All MCP SDKs| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 16 | MCP Python SDK: WebSocket server transport does not support Host/Origin validation | High | 1.28.1 |
| Jul 16 | MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal | High7.1 | 1.27.2 |
| Feb 4 | @modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse | High7.1 | 1.26.0 |
| Jan 5 | Anthropic's MCP TypeScript SDK has a ReDoS vulnerability | High | 1.25.2 |
| Dec 22025 | Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default | High | 1.23.0 |
| Dec 22025 | Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default | High | 1.24.0 |