github.com/modelcontextprotocol/go-sdk
Ecosystem:
go
go
Package URL:
pkg:golang/github.com/modelcontextprotocol/go-sdk
Total PRs:
378 Dependabot PRs
378 Dependabot PRs
Latest PR:
17 days ago
17 days ago
Unique Repositories:
191 repositories
191 repositories
Unique Repos (30 days):
14 repositories
14 repositories
Security Advisories
Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk
GHSA-89xv-2j6f-qhc8
CVE-2026-33252
HIGH
published 3 months ago
• updated 19 days ago
The Go SDK's Streamable HTTP transport accepted browser-generated cross-site `POST` requests without validating the `Origin` header and without req...
Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk
GHSA-q382-vc8q-7jhj
HIGH
published 3 months ago
• updated 20 days ago
The Go SDK recently transitioned to the `segmentio/encoding` library for JSON parsing in version 1.3.1. While this change addressed both case-insen...
DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost
GHSA-xw59-hvm2-8pj6
CVE-2026-34742
HIGH
published 3 months ago
• updated 9 days ago
The Model Context Protocol (MCP) Go SDK does not enable DNS rebinding protection by default for HTTP-based servers. When an HTTP-based MCP server i...
MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity
GHSA-wvj2-96wp-fq3f
CVE-2026-27896
HIGH
published 4 months ago
• updated 6 days ago
The Go MCP SDK used Go's standard encoding/json.Unmarshal for JSON-RPC and MCP protocol message parsing. Go's standard library performs case-insens...
Recent PRs (filtered by: Merged , Patch PRs )
Bump github.com/modelcontextprotocol/go-sdk from 0.3.0 to 0.3.1
baely/officetracker #127
0.3.0 → 0.3.1
Patch PR
Merged
10 months ago
chore(deps): bump github.com/modelcontextprotocol/go-sdk from 0.3.0 to 0.3.1
0.3.0 → 0.3.1
Patch PR
Merged
10 months ago
Package Details
| Name: | github.com/modelcontextprotocol/go-sdk |
| Ecosystem: | go |
| PURL Type: | golang |
| Package URL: | pkg:golang/github.com/modelcontextprotocol/go-sdk |
| JSON API: | View JSON |
Security Advisories
Package Information
Description:
| Repository: | https://github.com/modelcontextprotocol/go-sdk |
| Homepage: | https://github.com/modelcontextprotocol/go-sdk |
| Latest Release: |
v0.1.0
12 months ago |
| Dependent Repos: | 0 |
| Dependent Packages: | 0 |
| Ranking: | Top 5.6698% by dependent repos Top 5.3127% by dependent pkgs |