{"data":{"id":"8ed6e188-9f8f-4757-8b48-b418fd972f83","title":"GHSA-33f5-2c5q-wgwj: RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery","summary":"The rmcp library does not validate the resource field in OAuth Protected Resource metadata (RFC 9728), so a malicious MCP server can point an OAuth flow at a legitimate authorization server. The victim completes the authorization prompt, and the resulting access token, valid for the legitimate server, is sent to the attacker's server, which can then impersonate the victim. All MCP clients built on rmcp that use OAuth-protected MCP servers are affected.","solution":"Recommended fix: (1) Add a `resource: Option<String>` field to the `ResourceServerMetadata` struct in `crates/rmcp/src/transport/auth.rs`. (2) After fetching the metadata, compare the `resource` value with the configured base URL (ignoring trailing slashes) and return a `MetadataError` on mismatch.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-33f5-2c5q-wgwj","publishedAt":"2026-09-16T22:13:26.000Z","cveId":"CVE-2026-63127","cweIds":["CWE-345"],"cvssScore":"8.2","cvssSeverity":"high","severity":"high","attackType":["other"],"issueType":"vulnerability","affectedPackages":["rmcp@< 2.0.0 (fixed: 2.0.0)"],"affectedPackageNames":["rmcp"],"affectedPackageRefs":["cargo:rmcp"],"affectedVendors":[],"affectedVendorsRaw":["rmcp","MCP (Model Context Protocol)"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"required","exploitMaturity":"unknown","epssScore":0.00203,"epssCheckedAt":"2026-10-10T04:57:26.094Z","kevDateAdded":null,"advisoryAliases":["GHSA-33f5-2c5q-wgwj"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2026-09-16T22:13:26.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}