CVE-2026-55605: CWE-306: Missing Authentication for Critical Function in arikusi deepseek-mcp-server
DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to version 1.8.0, the self-hosted HTTP transport of `@arikusi/deepseek-mcp-server` exposes `POST /mcp` without any authentication: `createMcpExpressApp` is called without an `authProvider` and no middleware guards the route, so any network-reachable client can issue an unauthenticated `initialize` request and obtain a valid MCP session identifier. In reproduced testing against commit `5e1302171e99`, an unauthenticated client was able to initialize a session, enumerate tools, and invoke the local `deepseek_sessions` tool with no credentials. The same unauthenticated session also exposes `deepseek_chat`, whose handler uses the server-side `DEEPSEEK_API_KEY` when self-hosted deployments configure one. This issue applies to self-hosted HTTP mode, not the separately documented hosted BYOK endpoint in `README.md`, which expects an `Authorization: Bearer ...` header. Upstream self-hosted container assets enable HTTP mode by default (`Dockerfile`) and publish port `3000` (`docker-compose.yml`). Version 1.8.0 contains a patch for this issue.
AI Analysis
Technical Summary
The deepseek-mcp-server component of arikusi exposes a critical function via the POST /mcp HTTP endpoint without authentication in versions >=1.4.2 and <1.8.0. The server's createMcpExpressApp function is called without an authProvider, leaving the route unguarded. This allows any network-reachable client to send unauthenticated initialize requests, obtain valid MCP session identifiers, enumerate available tools, and invoke local tools such as deepseek_sessions and deepseek_chat. The deepseek_chat handler uses the server-side DEEPSEEK_API_KEY if configured, potentially exposing sensitive functionality. This vulnerability applies only to self-hosted HTTP mode, not the hosted BYOK endpoint which requires authorization. The issue is fixed in version 1.8.0.
Potential Impact
An unauthenticated attacker on the network can initialize MCP sessions and invoke local tools without credentials, potentially leading to unauthorized access to server functionality. The vulnerability does not impact confidentiality or integrity directly but results in availability impact due to unauthorized session initialization and tool invocation. The CVSS score is 5.3 (medium severity) reflecting network attack vector, no privileges required, no user interaction, and limited impact on availability only.
Mitigation Recommendations
Upgrade to version 1.8.0 or later, where this authentication bypass vulnerability is patched. Until then, restrict network access to the self-hosted HTTP transport on port 3000 to trusted clients only. Note that the hosted BYOK endpoint is not affected and requires authorization. Patch status is not explicitly stated but version 1.8.0 contains the fix; therefore, upgrading is the recommended remediation.
CVE-2026-55605: CWE-306: Missing Authentication for Critical Function in arikusi deepseek-mcp-server
Description
DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to version 1.8.0, the self-hosted HTTP transport of `@arikusi/deepseek-mcp-server` exposes `POST /mcp` without any authentication: `createMcpExpressApp` is called without an `authProvider` and no middleware guards the route, so any network-reachable client can issue an unauthenticated `initialize` request and obtain a valid MCP session identifier. In reproduced testing against commit `5e1302171e99`, an unauthenticated client was able to initialize a session, enumerate tools, and invoke the local `deepseek_sessions` tool with no credentials. The same unauthenticated session also exposes `deepseek_chat`, whose handler uses the server-side `DEEPSEEK_API_KEY` when self-hosted deployments configure one. This issue applies to self-hosted HTTP mode, not the separately documented hosted BYOK endpoint in `README.md`, which expects an `Authorization: Bearer ...` header. Upstream self-hosted container assets enable HTTP mode by default (`Dockerfile`) and publish port `3000` (`docker-compose.yml`). Version 1.8.0 contains a patch for this issue.
CVSS v3.1
Score 5.3medium
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The deepseek-mcp-server component of arikusi exposes a critical function via the POST /mcp HTTP endpoint without authentication in versions >=1.4.2 and <1.8.0. The server's createMcpExpressApp function is called without an authProvider, leaving the route unguarded. This allows any network-reachable client to send unauthenticated initialize requests, obtain valid MCP session identifiers, enumerate available tools, and invoke local tools such as deepseek_sessions and deepseek_chat. The deepseek_chat handler uses the server-side DEEPSEEK_API_KEY if configured, potentially exposing sensitive functionality. This vulnerability applies only to self-hosted HTTP mode, not the hosted BYOK endpoint which requires authorization. The issue is fixed in version 1.8.0.
Potential Impact
An unauthenticated attacker on the network can initialize MCP sessions and invoke local tools without credentials, potentially leading to unauthorized access to server functionality. The vulnerability does not impact confidentiality or integrity directly but results in availability impact due to unauthorized session initialization and tool invocation. The CVSS score is 5.3 (medium severity) reflecting network attack vector, no privileges required, no user interaction, and limited impact on availability only.
Mitigation Recommendations
Upgrade to version 1.8.0 or later, where this authentication bypass vulnerability is patched. Until then, restrict network access to the self-hosted HTTP transport on port 3000 to trusted clients only. Note that the hosted BYOK endpoint is not affected and requires authorization. Patch status is not explicitly stated but version 1.8.0 contains the fix; therefore, upgrading is the recommended remediation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-16T23:31:22.445Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a50171468715ace431ea19c
Added to database: 07/09/2026, 21:48:04 UTC
Last enriched: 07/17/2026, 09:58:16 UTC
Last updated: 08/22/2026, 22:52:14 UTC
Views: 59
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.