MCPP-TRN08: Weak Mcp-Session-Id¶
| Family | Transport |
| Default severity | high |
| Confidence | high |
| Mode | passive (default scan) |
| Spec revisions | 2025-03-26 to 2025-11-25 |
Why it matters¶
Session IDs SHOULD be globally unique and cryptographically secure and MUST contain only visible ASCII. Guessable identifiers let an attacker inject events into or hijack another user's session.
Remediation¶
Generate session IDs from a CSPRNG with at least 128 bits of entropy (e.g. secrets.token_urlsafe(32) or a random UUIDv4), bind them to the authenticated user, and never reuse them.
References¶
Suppressing¶
# .mcp-posture-ignore
[[ignore]]
check = "MCPP-TRN08"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31