PatchSiren

arikusi CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM arikusi CVE published 2026-07-09

CVE-2026-55605

CVE-2026-55605 is a vulnerability in DeepSeek MCP Server versions 1.4.2 to 1.7.0. The self-hosted HTTP transport exposes the `POST /mcp` endpoint without authentication, allowing clients to initialize a session and enumerate tools. The issue was patched in version 1.8.0. This vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. Users of DeepSeek MCP Server in self-hosted HTTP mode, especially t [truncated]

HIGH arikusi CVE published 2026-07-09

CVE-2026-55604

CVE-2026-55604 is a high-severity vulnerability in DeepSeek MCP Server, allowing attackers to enumerate and reuse session IDs, potentially leading to sensitive information disclosure. The vulnerability affects DeepSeek MCP Server versions 1.4.2 to 1.6.0 and is patched in version 1.7.0. This vulnerability has a high CVSS score of 8.6 and is considered HIGH severity. Users of affected versions should priori [truncated]