Fetching from the wire…
Public story · 2026-03-22 · source-backed
A security control bypass in the MCP Go SDK allows tool names like "Delete" vs "delete" to bypass exact-match authorization checks. Any server using the Go SDK with exact-match permission enforcement is affected. Patched SDK version is available. Source
Each link below shares sources, entities, or timing with this story.
MCP uses Go SDK / Shared entity: CVE / Shared topic / What happened next / Tension
Linked by a graph relationship (MCP uses Go SDK); both cover CVE; overlapping topics (security, server, tool).
MCP uses Go SDK / Shared entity: CVE / Shared topic / What happened next
Linked by a graph relationship (MCP uses Go SDK); both cover CVE; overlapping topics (authorization, check, server, tool).
Shared entities / Shared topic / Earlier coverage
Both cover CVE, MCP Go SDK; overlapping topics (bypass, case-insensitive, security, tool); earlier CVE coverage from 2026-02-28.
MCP uses Go SDK / Shared entity: CVE / Shared topic / What happened next
Linked by a graph relationship (MCP uses Go SDK); both cover CVE; overlapping topics (control, server, tool).
Linked by a graph relationship (MCP uses Go SDK); both cover CVE; overlapping topics (authorization, bypass, control).
MCP uses Go SDK / Shared entity: CVE / Shared topic / Earlier coverage
Linked by a graph relationship (MCP uses Go SDK); both cover CVE; overlapping topics (bypass, check, server).
MCP uses Go SDK / Shared entity: CVE / Shared topic / What happened next
Linked by a graph relationship (MCP uses Go SDK); both cover CVE; overlapping topics (server, tool).
Linked by a graph relationship (MCP uses Go SDK); both cover CVE; overlapping topics (server, tool).