Skip to content
HighVulnerability

GHSA-89vp-x53w-74fx: rmcp Streamable HTTP server transport has a DNS rebinding vulnerability

Published
Record updated
View JSON
Affected
  • rmcp < 1.4.0
Fixed in
1.4.0
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.2%

Summary

Prior to version 1.4.0, the rmcp crate's Streamable HTTP server transport did not validate the incoming Host header, so a malicious public website using a DNS rebinding attack could send authenticated requests to a local or private-network MCP server. An attacker could enumerate and invoke exposed tools and read resources, and because MCP servers often run with the user's privileges, the impact can extend to arbitrary code execution on the victim's machine.

Mitigation

Fixed in rmcp 1.4.0 (PR #764, commit 8e22aa2): StreamableHttpServerConfig::allowed_hosts now defaults to a loopback-only allowlist, and requests whose Host header is not on the allowlist receive HTTP 403. Upgrade to rmcp >= 1.4.0. If upgrade is not possible, place the MCP server behind a reverse proxy configured to reject requests whose Host header is not an expected hostname, and do not bind the server to 0.0.0.0 without such a proxy.