漏洞描述
Detects a Model Context Protocol server exposing the Streamable HTTP transport that completes the JSON-RPC 2.0 `initialize` handshake without any credentials. The MCP lifecycle requires `initialize` to be the first interaction on a connection, and a spec-compliant server answers it with an InitializeResult carrying `protocolVersion`, `capabilities` and `serverInfo`. Receiving that result from an unauthenticated POST shows the endpoint performs no authorization before entering the operation phase, so any caller can go on to enumerate and invoke the tools, resources and prompts the server exposes.
影响产品
暂无结构化产品信息。
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。