Skip to content
HighVulnerability

GHSA-xw59-hvm2-8pj6: DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost

Published
Record updated
View JSON
Affected
  • github.com/modelcontextprotocol/go-sdk < 1.4.0
Fixed in
1.4.0
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.7%

Summary

The Model Context Protocol (MCP) Go SDK does not enable DNS rebinding protection by default for HTTP-based servers. A malicious website could use DNS rebinding to bypass same-origin restrictions and send requests to an HTTP-based MCP server running on localhost without authentication, using `StreamableHTTPHandler` or `SSEHandler`. This could let an attacker invoke tools or access resources on the user's behalf, and servers using stdio transport are not affected.

Mitigation

Fixed in 1.4.0: servers created via `StreamableHTTPHandler` or `SSEHandler` now have DNS rebinding protection enabled by default when binding to `localhost`. Users are advised to update to version 1.4.0.