MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to versions 1.0.1 and 1.1.1, there is a hardcoded wildcard CORS vulnerability. This issue has been patched in versions 1.0.1 and 1.1.1.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 2
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Lfprojects Mcp_Java_Sdk
cpe:2.3:a:lfprojects:mcp_java_sdk:*:*:*:*:*:*:*:*
|
— |
1.0.1
|
|
Lfprojects Mcp_Java_Sdk
cpe:2.3:a:lfprojects:mcp_java_sdk:1.1.0:*:*:*:*:*:*:*
|
— | — |