Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
📦
📦 npm
Not in CISA KEV
HIGH severity

@arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled KeyGHSA-fh3r-g96v-f578

HIGH

GHSA-fh3r-g96v-f578 is a high-severity (CVSS 8.6) CWE-639 vulnerability in @arikusi/deepseek-mcp-server. A fix is available for @arikusi/deepseek-mcp-server — see the affected versions and patch details below.

Also known asCVE-2026-55604
Published
Updated
Affected
1 pkg
Patched
1 / 1
Exploits
None indexed
Exploitation data as of Oct 9, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Exploitation Status

No confirmed exploitation observed yet

  • CISA assesses this as automatable — exploitation doesn’t require manual, per-target effort, which raises the odds of mass scanning and opportunistic attacks.
  • CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.

Exploitation and automatability from CISA’s SSVC triage for GHSA-fh3r-g96v-f578.

EPSS Exploitation Probability

via FIRST.org ↗
0.4%probability of exploitation in next 30 days
Lower Risk0.00%
Lower risk than most CVEs29th percentile — riskier than 29% of all scored CVEsHighest risk
0.00%0.29%0.58%0.87%0.2%0.4%0.4%Aug 26Oct 26Oct 26

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

How urgent is this, really

GHSA-fh3r-g96v-f578 by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.

Where this sits among everything scored

Of 384,993 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.

Real-World Exposure

1 pkg affected

How broadly this vulnerability is actually deployed: weekly install volume shows current usage, and reverse-dependency count shows how many other packages break if it stays unpatched.

0other npm packages depend on this — each one inherits the vulnerability until it's patched upstream
@arikusi/deepseek-mcp-servernpm
535downloads / week

Description

Cross-Session Data Exposure via Caller-Controlled session_id

Project / Repository: arikusi/deepseek-mcp-server
Affected version / commit tested: 1.6.0 / 04f28be2c6e99d3d4e443a6ae37cc35f0a71554a
Vulnerability type: Authorization bypass / cross-session data exposure Authentication required: No

Summary

The process-global SessionStore accepts caller-supplied session_id values without binding them to any authenticated principal or transport session. An attacker can enumerate active session IDs via deepseek_sessions, then reuse a victim-controlled session_id in deepseek_chat to retrieve and continue the victim's conversation context.

Affected Code

  • src/session.ts:42 - caller-controlled session IDs are looked up directly from the global in-memory map.
  • src/session.ts:67 - a new session is stored under the caller-controlled ID without ownership binding.
  • src/session.ts:109 - getMessages() retrieves messages for any supplied session ID.
  • src/tools/deepseek-chat.ts:195 - deepseek_chat creates or reuses the supplied session_id.
  • src/tools/deepseek-chat.ts:197 - previous messages are loaded from the supplied session_id.
  • src/tools/deepseek-chat.ts:198 - previous messages are prepended into the attacker-controlled request.
  • src/tools/deepseek-chat.ts:243 - attacker-provided user messages are appended into the reused session.
  • src/tools/deepseek-chat.ts:245 - assistant responses are appended back into the reused session.
  • src/tools/deepseek-sessions.ts:37 - deepseek_sessions list enumerates all active sessions.
  • src/tools/deepseek-sessions.ts:53 - each enumerated session ID is rendered back to the caller.

PoC Overview

  1. Create a victim conversation with session_id = "victim-session".
  2. Call deepseek_sessions with action = "list" and observe that victim-session is disclosed.
  3. Call deepseek_chat again with session_id = "victim-session" from a separate attacker flow.
  4. The upstream request now includes the victim's prior messages before the attacker's message.

Validation Environment

Local runtime verification on Windows host with Node.js v24.11.1, using the repository code at the tested commit and a local mock DeepSeek client to capture the effective message list passed upstream.

Impact

Any reachable caller can enumerate active session IDs and read prior conversation history stored in memory for other callers within the same server process. The same flaw also allows attacker-controlled continuation of another user's session state.

Remediation

  • Bind stored sessions to an authenticated transport session or other server-generated opaque identifier.
  • Do not allow arbitrary user-supplied session_id values to select existing server-side state.
  • Remove or restrict deepseek_sessions list so it does not disclose unrelated session IDs.
  • Reject reuse of a session unless the caller proves ownership of that session.

Attached Evidence

01_deepseek-mcp-server_cross_session_data_exposure.txt


Patches (maintainer)

Fixed in 1.7.0. The HTTP transport's SessionStore is no longer a process-wide singleton: each MCP HTTP session gets its own store, injected into the deepseek_chat and deepseek_sessions tool handlers, so a session_id from one HTTP session cannot read, enumerate, or clear another session's state. STDIO transport was never affected (one process per client). Integration tests in src/transport-isolation.test.ts assert the isolation.

Affected versions >=1.4.2, <1.7.0 are deprecated on npm. Upgrade to 1.7.0 or later.

Workaround

If upgrading is not immediately possible, run in STDIO transport (unset TRANSPORT=http) or stop the HTTP server.

Credit

Reported independently by @232-323 and @2REBCat (tested against 1.6.0). The same root cause was found and fixed concurrently by the maintainer during a security audit, shipped in 1.7.0. All parties are credited as finders.

Note on severity

A connected client could read other clients' conversation history (C:H), inject messages into their sessions (I:L), and clear or delete other clients' sessions (A:L). Scope is unchanged: the impact stays within the application's own authorization boundary, which is a cross-tenant authorization bypass, so S:U is correct.

Affected Packages

1 total 1 fixed
EcosystemPackageVulnerable rangeFix
📦npm@arikusi/deepseek-mcp-server≥ 1.4.2&&< 1.7.01.7.0npm install @arikusi/deepseek-mcp-server@1.7.0

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for @arikusi/deepseek-mcp-server, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    Update @arikusi/deepseek-mcp-server to 1.7.0 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-fh3r-g96v-f578 is resolved across your whole dependency graph.

  3. Workarounds

    If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.

Frequently Asked Questions

# Cross-Session Data Exposure via Caller-Controlled `session_id` Project / Repository: `arikusi/deepseek-mcp-server` Affected version / commit tested: `1.6.0` / `04f28be2c6e99d3d4e443a6ae37cc35f0a71554a` Vulnerability type: Authorization bypass / cross-session data exposure Authentication required: No ## Summary The process-global `SessionStore` accepts caller-supplied `session_id` values without binding them to any authenticated principal or transport session. An attacker can enumerate active session IDs via `deepseek_sessions`, then reuse a victim-controlled `session_id` in `deepseek_
O3 Security · Impact-Aware SCA

Is GHSA-fh3r-g96v-f578 in your dependencies?

Find it across npm, including transitive dependencies.

@arikusi/deepseek-mcp-server has an Authorization…