CVE-2026-33252 | modelcontextprotocol go-sdk up to 1.4.0 Content-Type cross-site request forgery (GHSA-89xv-2j6f-qhc8)
A vulnerability was found in modelcontextprotocol go-sdk up to 1.4.0. It has been rated as problematic. This impacts an unknown function of the component Content-Type Handler. The manipulation leads to cross-site request forgery.
This vulnerability is referenced as CVE-2026-33252. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.