Categories USA News

MCP attack abuses predictable session IDs to hijack AI agents

The vuln affects the Oat++ MCP implementation

A security flaw in the Oat++ implementation of Anthropic’s Model Context Protocol (MCP) allows attackers to predict or capture session IDs from active AI conversations, hijack MCP sessions, and inject malicious responses via the oatpp-mcp server.…

More From Author

You May Also Like

Judge blocks Trump administration from withholding transportation funds over immigration enforcement

Illinois, along with 19 other states, won yet another victory in court Tuesday, with a…

Ohio State, Indiana top season’s first College Football Playoff rankings

Ohio State received top billing in the first College Football Playoff rankings of the season…

Fire damages Albany Park apartment building

No one was hurt after a fire engulfed an Albany Park apartment building Tuesday afternoon.…