CVE-2026-33946 | modelcontextprotocol ruby-sdk up to 0.9.1 streamable_http_transport.rb session fixiation
A vulnerability categorized as critical has been discovered in modelcontextprotocol ruby-sdk up to 0.9.1. This issue affects some unknown processing of the file streamable_http_transport.rb. Such manipulation leads to session fixiation.
This vulnerability is traded as CVE-2026-33946. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.