GHSA-89xv-2j6f-qhc8: Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk
- Identifiers
- CVE-2026-33252GHSA-89xv-2j6f-qhc8
- Published
- Record updated
- Affected
- github.com/modelcontextprotocol/go-sdk <= 1.4.0
- Fixed in
- 1.4.1
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.2%
Summary
The Go SDK for MCP (github.com/modelcontextprotocol/go-sdk) had a flaw in its Streamable HTTP transport. It accepted browser-generated cross-site POST requests without validating the Origin header or requiring Content-Type: application/json. Without Authorization configured, especially in stateless or sessionless setups, any website could send MCP requests to a local server and potentially trigger tool execution. Cross-site POSTs with Content-Type: text/plain could reach message handling without a CORS preflight barrier.
Mitigation
Fixed in v1.4.1, which adds Content-Type header validation for POST requests and a configurable origin verification protection (commit a433a83). Note: v1.4.1 requires Go 1.25 or later.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- github.com/modelcontextprotocol/go-sdkGoLLM dependency since 2025-07-01 · 1 tracked dependent
Topics
Related items
- LowAnthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection FlawsSimilar attack · The Hacker News
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpointsSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- CriticalHermes Agent - PKCE Session Takeover via Redirect-URI Parser ConfusionSimilar attack · Tenable Research Advisories
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading