Description
MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to versions 1.0.1 and 1.1.1, there is a hardcoded wildcard CORS vulnerability. This issue has been patched in versions 1.0.1 and 1.1.1.
Problem types
CWE-942: Permissive Cross-domain Policy with Untrusted Domains
Product status
< 1.1.1
References
github.com/...va-sdk/security/advisories/GHSA-hv2w-8mjj-jw22
github.com/...ort/HttpServletSseServerTransportProvider.java
github.com/...pServletStreamableServerTransportProvider.java