Skip to content
MediumVulnerability

GHSA-c9xm-49cp-xcr9: rmcp OAuth client fetches server-controlled resource_metadata URLs

Published
Record updated
View JSON
Affected
  • rmcp < 2.0.0
Fixed in
2.0.0

Summary

The rmcp OAuth client in modelcontextprotocol/rust-sdk takes a resource_metadata URL from the server-controlled WWW-Authenticate header and fetches it without same-origin or private-network checks. A malicious or compromised MCP server can point the client at localhost, RFC 1918 addresses or cloud metadata endpoints, making the victim application send outbound GET requests from its own network context.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.