MCPP-TRN07: Session identifier carried in a URL¶
| Family | Transport |
| Default severity | high |
| Confidence | high |
| Mode | passive (default scan) |
| Spec revisions | all |
Why it matters¶
URLs end up in access logs, proxies, browser history and Referer headers. A session identifier in a URL can be replayed by anyone who reads those logs (session hijacking).
Remediation¶
Carry the session only in the Mcp-Session-Id header (Streamable HTTP), never in a query string or path.
References¶
Suppressing¶
# .mcp-posture-ignore
[[ignore]]
check = "MCPP-TRN07"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31