Vulnerabilities
Vulnerable Software
The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_server transport accepted WebSocket handshakes without applying Host or Origin header validation, leaving no SDK-level way to restrict which origins could connect to applications that exposed that transport. This issue is fixed in version 1.28.1.
CVSS Score
7.6
EPSS Score
0.002
Published
2026-07-15


Contact Us

Shodan ® - All rights reserved