GHSA-33f5-2c5q-wgwj: RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery
- Identifiers
- CVE-2026-63127GHSA-33f5-2c5q-wgwj
- Published
- Record updated
- Affected
- rmcp < 2.0.0
- Fixed in
- 2.0.0
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.2%
Summary
The rmcp library does not validate the resource field in OAuth Protected Resource metadata (RFC 9728), so a malicious MCP server can point an OAuth flow at a legitimate authorization server. The victim completes the authorization prompt, and the resulting access token, valid for the legitimate server, is sent to the attacker's server, which can then impersonate the victim. All MCP clients built on rmcp that use OAuth-protected MCP servers are affected.
Mitigation
Recommended fix: (1) Add a `resource: Option<String>` field to the `ResourceServerMetadata` struct in `crates/rmcp/src/transport/auth.rs`. (2) After fetching the metadata, compare the `resource` value with the configured base URL (ignoring trailing slashes) and return a `MetadataError` on mismatch.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- rmcpcrates.ioLLM dependency since 2025-03-16
Topics
Related items
- LowAnthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection FlawsSimilar attack · The Hacker News
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpointsSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- CriticalHermes Agent - PKCE Session Takeover via Redirect-URI Parser ConfusionSimilar attack · Tenable Research Advisories
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading