Skip to content
HighVulnerability

GHSA-33f5-2c5q-wgwj: RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery

Published
Record updated
View JSON
Affected
  • rmcp < 2.0.0
Fixed in
2.0.0
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.2%

Summary

The rmcp library does not validate the resource field in OAuth Protected Resource metadata (RFC 9728), so a malicious MCP server can point an OAuth flow at a legitimate authorization server. The victim completes the authorization prompt, and the resulting access token, valid for the legitimate server, is sent to the attacker's server, which can then impersonate the victim. All MCP clients built on rmcp that use OAuth-protected MCP servers are affected.

Mitigation

Recommended fix: (1) Add a `resource: Option<String>` field to the `ResourceServerMetadata` struct in `crates/rmcp/src/transport/auth.rs`. (2) After fetching the metadata, compare the `resource` value with the configured base URL (ignoring trailing slashes) and return a `MetadataError` on mismatch.