CVE-2026-33252Disclosure(lfprojects / mcp_go_sdk)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch lfprojects mcp_go_sdk systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Go MCP SDK used Go's standard encoding/json. Prior to version 1.4.1, the Go SDK's Streamable HTTP transport accepted browser-generated cross-site `POST` requests without validating the `Origin` header and without requiring `Content-Type: application/json`. In deployments without Authorization, especially stateless or sessionless configurations, this allows an arbitrary website to send MCP requests to a local server and potentially trigger tool execution. Version 1.4.1 contains a patch for the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-352

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mcp_go_sdk

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-24); latest day: 2
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
mcp_go_sdk

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-03-24: 3Mentions · 2026-04-07: 2Patch / Workaround · 2026-03-24: 1Technical Details · 2026-03-24: 2Technical Details · 2026-04-07: 103-2404-07
Signal classification2 categories
Disclosure
360.0%
General
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-243
Disclosure2General1
2026-04-072
Disclosure1General1
Full discourse5 posts
  • Firmis Labs@FirmisLabs
    General

    CVE-2026-33252 · NIST 7.1/10 https://nvd.nist.gov/vuln/detail/CVE-2026-33252

    Post summary

    The post merely cites CVE-2026-33252 with its NIST CVSS score of 7.1 and provides a link to the NVD entry, offering no further technical or exploit information.

    1000028
    1 followersView on X
  • Firmis Labs@FirmisLabs
    Disclosure

    CVE-2026-33252 · NIST 7.1/10 https://nvd.nist.gov/vuln/detail/CVE-2026-33252

    Post summary

    The text merely points to the NVD entry for CVE-2026-33252, providing no additional technical or operational details.

    1000027
    1 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `Modelcontext Protocol Go SDK` (http://github.com/modelcontextprotocol/go-sdk) is affected by Cross-Site Tool Execution (CVE-2026-33252) impacting HTTP servers without authorization. Implement robust authorization. #Go #CyberSecurity #AuthBypass https://www.pulsepatch.io/posts/cve-2026-33252-modelcontext-protocol-go-sdk-cross-site-tool-execution

    Post summary

    CVE‑2026‑33252 causes Cross‑Site Tool Execution in Modelcontext Protocol Go SDK’s HTTP servers when authorization is missing, and recommends implementing robust authorization as a mitigation.

    0001028
    2 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-33252 📊 Severity: 7.1 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-33252 #CVE-2026-33252 #CVE #High #CyberSecurity #InfoSec https://t.co/7WSBr4CmM6

    Post summary

    The tweet simply alerts about CVE-2026-33252 with a high severity score, providing no technical details, exploit code, or mitigation information.

    0000026
    112 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33252 The Go MCP SDK used Go's standard encoding/json. Prior to version 1.4.1, the Go SDK's Streamable HTTP transport accepted browser-generated cross-site `POST` requests … https://www.cve.org/CVERecord?id=CVE-2026-33252

    Post summary

    The post describes a vulnerability in the Go MCP SDK (prior to v1.4.1) that allows browser‑generated cross‑site POST requests, but it does not provide a PoC, exploit code, or any patch information.

    00000149
    56.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applfprojectsmcp_go_sdk---

Explore more