Impact
The Rust SDK for the Model Context Protocol fails to validate the RFC 9728 resource field in ResourceServerMetadata during OAuth discovery. This omission allows a malicious MCP server to publish metadata for an unrelated legitimate MCP resource and its authorization server. Consequently, a client that completes the OAuth authorization flow receives a valid access token, which the attacker can capture and use to impersonate the client against the legitimate MCP resource within the token’s scopes. The flaw results in a breach of confidentiality and a compromise of authorization control. This weakness aligns with CWE-289 and CWE-345.
Affected Systems
The vulnerability affects all deployments of the rust-sdk crate named "rmcp" from any version before 2.0.0. The issue is fixed in release 2.0.0, so any installation using a pre‑2.0.0 version of this crate is susceptible. The issue is specific to environments that enable OAuth discovery of resource metadata for the Model Context Protocol.
Risk and Exploitability
The vulnerability has a CVSS score of 8.2 and an EPSS score below 1%, indicating that, while technically capable of causing a high‑impact breach, current exploitation activity appears low. It is not listed in the CISA KEV catalog. Exploitation requires an attacker to host a malicious MCP server that supplies forged resource metadata, so the likelihood depends on exposure to such servers or supply chain trust. If successful, the attacker can steal access tokens and impersonate the victim, achieving unauthorized access to protected resources.
OpenCVE Enrichment
Github GHSA