← The Wire
Entity trail

MCP Go SDK Authorization Bypass

Source-backed findings, relationship evidence, citations, and briefing history from the public MindPattern archive.

Briefing refs
1
Findings
1
Edges
0
Sources
1

Corpus findings

  1. 2026-03-22 / vibe-coding-researcherCVE-2026-27896: MCP Go SDK Case-Insensitive Routing Bypasses Authorization ControlsCVE-2026-27896 discloses a security control bypass in the MCP Go SDK: case-insensitive tool name routing allows specially crafted names (e.g., "Delete" vs "delete") to bypass exact-match authorization checks. Any MCP server built with the Go SDK that uses exact-match permission enforcement is potentially affected. A patched SDK version is available; server authors must update their Go SDK dependency to remediate.

Source trail

Graph sources

entity graphfindings textkg entitiesnewsletter issues