Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-55605— @arikusi/deepseek-mcp-server Missing Authentication on Self-Hosted HTTP MCP Endpoint

CVSS 5.3 · Medium EPSS 0.43% · P36

Possible ATT&CK Techniques 1AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProductVersion RangeStatus
arikusideepseek-mcp-server>= 1.4.2, < 1.8.0affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-55605

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
@arikusi/deepseek-mcp-server Missing Authentication on Self-Hosted HTTP MCP Endpoint
Source: CVE Program / CVE List V5
Vulnerability Description
DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to version 1.8.0, the self-hosted HTTP transport of `@arikusi/deepseek-mcp-server` exposes `POST /mcp` without any authentication: `createMcpExpressApp` is called without an `authProvider` and no middleware guards the route, so any network-reachable client can issue an unauthenticated `initialize` request and obtain a valid MCP session identifier. In reproduced testing against commit `5e1302171e99`, an unauthenticated client was able to initialize a session, enumerate tools, and invoke the local `deepseek_sessions` tool with no credentials. The same unauthenticated session also exposes `deepseek_chat`, whose handler uses the server-side `DEEPSEEK_API_KEY` when self-hosted deployments configure one. This issue applies to self-hosted HTTP mode, not the separately documented hosted BYOK endpoint in `README.md`, which expects an `Authorization: Bearer ...` header. Upstream self-hosted container assets enable HTTP mode by default (`Dockerfile`) and publish port `3000` (`docker-compose.yml`). Version 1.8.0 contains a patch for this issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
关键功能的认证机制缺失
Source: CVE Program / CVE List V5
Vulnerability Title
tahir DeepSeek MCP Server 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
tahir DeepSeek MCP Server是tahir个人开发者的一个实现MCP的服务器。 tahir DeepSeek MCP Server 1.4.2版本至1.8.0之前版本存在授权问题漏洞,该漏洞源于自托管HTTP传输暴露`POST /mcp`接口且未进行身份验证,可能导致任何网络可达客户端发起未认证的初始化请求并获取有效MCP会话标识符,进一步枚举工具及调用本地工具,在配置了服务器端API密钥时还可能暴露聊天功能。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
arikusideepseek-mcp-server >= 1.4.2, < 1.8.0 -

II. Public POCs for CVE-2026-55605

#POC DescriptionSource LinkShenlong Link
AI-Generated POCVerified env Premium
Reproduced successfully in a real sandbox· Below is the actual recording of building the environment and exploiting the vulnerability.
Reproduction recording is a Pro+ exclusive
Watch the full sandbox build + live exploit recording for this CVE. Limited-time ¥499/mo.
Upgrade to Pro+
claude_code · 12378 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-55605

登录查看更多情报信息。

Patches & Fixes for CVE-2026-55605 (1)

Vendor Advisories for CVE-2026-55605 (1)

Other References for CVE-2026-55605 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-55605

No comments yet


Leave a comment