hackwither_

reap / rules / auth and session posture

MCP session ID entropy looks weak or predictable

mcp-session-id-entropy ASI03 Identity and Privilege Abuse severity: medium

What it detects

Weak or predictable session identifiers — the value itself is never recorded in the finding. ASI03. Streamable-HTTP only.

Analyzes the Mcp-Session-Id header value for short length, small character set, repeated characters, or low estimated bit-entropy. Streamable-HTTP only.

applies to MCP endpoints

Why it matters

A guessable session ID lets an attacker assume another caller's identity directly.

OWASP ASI mapping rationale

Example finding

MEDIUM  mcp-session-id-entropy  HIGH CONFIDENCE
MCP session ID entropy looks weak or predictable
The MCP session ID returned by the server appears to have low entropy or a predictable format: session ID is shorter than 16 characters, estimated entropy is low (36 bits)

from a scan of reap-range, bad target

Fix

Use a cryptographically random, high-entropy session identifier for MCP sessions and avoid sequential or human-readable formats.

On reap-range

insecure targetbad/mcp · Medium (sess001)
correct targetgood/mcp sends a secrets.token_urlsafe(32) ID

Run only this check

reap -t https://your-host/mcp --authorized --include mcp-session-id-entropy

Not installed? Install REAP. Only scan systems you own or are authorised to test. Reference: docs/PROBES.md.