Description
RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's OAuth implementation in crates/rmcp/src/transport/auth.rs omits the RFC 9728 resource field from ResourceServerMetadata and allows discover_oauth_server_via_resource_metadata to use protected-resource metadata without confirming that the returned resource identifier exactly matches the configured MCP server. A malicious MCP server can publish metadata for a different legitimate MCP resource and its authorization server, causing a victim who connects and completes the authorization flow to obtain a legitimate access token that the client subsequently sends to the malicious server. The attacker can capture the token and impersonate the victim against the legitimate MCP resource within the token's granted scopes. This issue is fixed in version 2.0.0.
Published: 2026-09-16
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Token Acquisition and Impersonation
Action: Immediate Patch
AI Analysis

Impact

The Rust SDK for the Model Context Protocol fails to validate the RFC 9728 resource field in ResourceServerMetadata during OAuth discovery. This omission allows a malicious MCP server to publish metadata for an unrelated legitimate MCP resource and its authorization server. Consequently, a client that completes the OAuth authorization flow receives a valid access token, which the attacker can capture and use to impersonate the client against the legitimate MCP resource within the token’s scopes. The flaw results in a breach of confidentiality and a compromise of authorization control. This weakness aligns with CWE-289 and CWE-345.

Affected Systems

The vulnerability affects all deployments of the rust-sdk crate named "rmcp" from any version before 2.0.0. The issue is fixed in release 2.0.0, so any installation using a pre‑2.0.0 version of this crate is susceptible. The issue is specific to environments that enable OAuth discovery of resource metadata for the Model Context Protocol.

Risk and Exploitability

The vulnerability has a CVSS score of 8.2 and an EPSS score below 1%, indicating that, while technically capable of causing a high‑impact breach, current exploitation activity appears low. It is not listed in the CISA KEV catalog. Exploitation requires an attacker to host a malicious MCP server that supplies forged resource metadata, so the likelihood depends on exposure to such servers or supply chain trust. If successful, the attacker can steal access tokens and impersonate the victim, achieving unauthorized access to protected resources.

Generated by OpenCVE AI on September 18, 2026 at 03:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the rust‑sdk rmcp crate to version 2.0.0 or later, which enforces resource field validation during OAuth discovery.
  • Add custom validation in the application layer that explicitly checks the returned ResourceServerMetadata.resource field against the expected MCP server identifier before using the access token.
  • Implement network controls (e.g., firewall rules or reverse proxy) to restrict communication to known, trusted MCP servers and log all OAuth discovery requests for anomaly detection.

Generated by OpenCVE AI on September 18, 2026 at 03:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-33f5-2c5q-wgwj RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery
History

Fri, 18 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
First Time appeared Modelcontextprotocol
Modelcontextprotocol rust-sdk
Vendors & Products Modelcontextprotocol
Modelcontextprotocol rust-sdk

Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-289
References
Metrics threat_severity

None

threat_severity

Important


Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's OAuth implementation in crates/rmcp/src/transport/auth.rs omits the RFC 9728 resource field from ResourceServerMetadata and allows discover_oauth_server_via_resource_metadata to use protected-resource metadata without confirming that the returned resource identifier exactly matches the configured MCP server. A malicious MCP server can publish metadata for a different legitimate MCP resource and its authorization server, causing a victim who connects and completes the authorization flow to obtain a legitimate access token that the client subsequently sends to the malicious server. The attacker can capture the token and impersonate the victim against the legitimate MCP resource within the token's granted scopes. This issue is fixed in version 2.0.0.
Title RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery
Weaknesses CWE-345
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N'}


Subscriptions

Modelcontextprotocol Rust-sdk
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T15:39:26.956Z

Reserved: 2026-07-15T16:54:55.816Z

Link: CVE-2026-63127

cve-icon Vulnrichment

Updated: 2026-09-16T15:38:59.771Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T15:17:39.817

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-63127

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-16T14:50:54Z

Links: CVE-2026-63127 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T05:00:03Z

Weaknesses
  • CWE-289

    Authentication Bypass by Alternate Name

  • CWE-345

    Insufficient Verification of Data Authenticity