Skip to content
HighVulnerability

GHSA-89xv-2j6f-qhc8: Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk

Published
Record updated
View JSON
Affected
  • github.com/modelcontextprotocol/go-sdk <= 1.4.0
Fixed in
1.4.1
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.2%

Summary

The Go SDK for MCP (github.com/modelcontextprotocol/go-sdk) had a flaw in its Streamable HTTP transport. It accepted browser-generated cross-site POST requests without validating the Origin header or requiring Content-Type: application/json. Without Authorization configured, especially in stateless or sessionless setups, any website could send MCP requests to a local server and potentially trigger tool execution. Cross-site POSTs with Content-Type: text/plain could reach message handling without a CORS preflight barrier.

Mitigation

Fixed in v1.4.1, which adds Content-Type header validation for POST requests and a configurable origin verification protection (commit a433a83). Note: v1.4.1 requires Go 1.25 or later.