CVE-2026-33252 PUBLISHED CVSS 7.099999904632568 HIGH

The Go MCP SDK used Go's standard encoding/json. Prior to version 1.4.1, the Go SDK's Streamable HTTP transport accepted browser-generated cross-site `POST` requests without validating the `Origin` header and without requiring `Content-Type: application/json`. In deployments without Authorization, especially stateless or sessionless configurations, this allows an arbitrary website to send MCP requests to a local server and potentially trigger tool execution. Version 1.4.1 contains a patch for the issue.

EPSS 0.01% · 0.4th percentile

Risk Scores

CVSS v3.1
7.099999904632568
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L
EPSS Score
0.01%
0.4th percentile

Affected Products

VendorProductVersions
github.commodelcontextprotocol/go-sdk0, 0, 0
modelcontextprotocolgo-sdk< 1.4.1, < 1.4.1, < 1.4.1

Timeline

References

Open in Interactive Console →