Impact
The vulnerability lies in RMCP's default HTTP client configuration. The client follows HTTP redirects automatically and replays any custom HTTP headers supplied by the user. When a malicious or compromised Model Context Protocol endpoint issues a cross‑origin 307 or 308 redirect, those custom headers can contain API keys or authentication tokens. The redirect causes the client to resend those headers to the new origin, allowing an attacker to capture and reuse the credentials. This results in accidental credential leakage and potential unauthorized access to services where the tokens are valid. The weakness is a data‑exposure flaw (CWE‑200) and an improper handling of sensitive headers (CWE‑212).
Affected Systems
The vulnerability affects the modelcontextprotocol rust-sdk, specifically the rmcp crate’s StreamableHttpClientTransport implementation. Versions earlier than 2.1.0 are vulnerable; the issue is fixed in 2.1.0.
Risk and Exploitability
The CVSS score is 6.8, indicating a moderate severity. The EPSS score is below 1%, suggesting that, as of the latest reporting, exploitation attempts have been very rare. The vulnerability is not listed in CISA’s KEV catalog. The likely exploitation path requires an attacker to influence the SDK to issue a request to a controlled endpoint that issues a cross‑origin redirect, after which the SDK automatically follows the redirect and repeats the headers. Because the redirect policy is automatic, the attack can be performed without additional configuration changes on the client side, though the attacker must have control over an endpoint contactable by the SDK or compromise an MCP endpoint to inject the redirect. The risk is primarily that an attacker who can observe or control the flow may ingest the leaked credentials and use them to access other services. The low EPSS score indicates that such attacks are currently rare, but the impact of credential theft warrants prompt mitigation.
OpenCVE Enrichment
Github GHSA