{"data":{"id":"deeed998-63ac-4429-83af-0a8a59f68a13","title":"GHSA-89xv-2j6f-qhc8: Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk","summary":"The Go SDK for MCP (github.com/modelcontextprotocol/go-sdk) had a flaw in its Streamable HTTP transport. It accepted browser-generated cross-site POST requests without validating the Origin header or requiring Content-Type: application/json. Without Authorization configured, especially in stateless or sessionless setups, any website could send MCP requests to a local server and potentially trigger tool execution. Cross-site POSTs with Content-Type: text/plain could reach message handling without a CORS preflight barrier.","solution":"Fixed in v1.4.1, which adds Content-Type header validation for POST requests and a configurable origin verification protection (commit a433a83). Note: v1.4.1 requires Go 1.25 or later.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-89xv-2j6f-qhc8","publishedAt":"2026-03-19T16:42:40.000Z","cveId":"CVE-2026-33252","cweIds":["CWE-352"],"cvssScore":"7.1","cvssSeverity":"high","severity":"high","attackType":["other"],"issueType":"vulnerability","affectedPackages":["github.com/modelcontextprotocol/go-sdk@<= 1.4.0 (fixed: 1.4.1)"],"affectedPackageNames":["github.com/modelcontextprotocol/go-sdk"],"affectedPackageRefs":["go:github.com/modelcontextprotocol/go-sdk"],"affectedVendors":[],"affectedVendorsRaw":["MCP Go SDK","Model Context Protocol"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"required","exploitMaturity":"unknown","epssScore":0.00212,"epssCheckedAt":"2026-10-10T04:57:23.098Z","kevDateAdded":null,"advisoryAliases":["GHSA-89xv-2j6f-qhc8"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2026-03-19T16:42:40.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}