{"data":{"id":"99fc6cfa-bcd9-4bdd-b5a3-5202f17546b1","title":"GHSA-c9xm-49cp-xcr9: rmcp OAuth client fetches server-controlled resource_metadata URLs","summary":"The rmcp OAuth client in modelcontextprotocol/rust-sdk takes a resource_metadata URL from the server-controlled WWW-Authenticate header and fetches it without same-origin or private-network checks. A malicious or compromised MCP server can point the client at localhost, RFC 1918 addresses or cloud metadata endpoints, making the victim application send outbound GET requests from its own network context.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-c9xm-49cp-xcr9","publishedAt":"2026-10-02T16:12:31.000Z","cveId":null,"cweIds":["CWE-918"],"cvssScore":null,"cvssSeverity":"medium","severity":"medium","attackType":["other"],"issueType":"vulnerability","affectedPackages":["rmcp@< 2.0.0 (fixed: 2.0.0)"],"affectedPackageNames":["rmcp"],"affectedPackageRefs":["cargo:rmcp"],"affectedVendors":[],"affectedVendorsRaw":["rmcp","MCP (Model Context Protocol)"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":["GHSA-c9xm-49cp-xcr9"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2026-10-02T16:12:31.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}