{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3armcp_projectrmcprust/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:rmcp_project:rmcp:*:*:*:*:*:rust:*:*"],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-63127"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["rmcp (\u003c 2.0.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Rust"],"content_html":"\u003cp\u003eThe \u003ccode\u003ermcp\u003c/code\u003e Rust library, used for building Model Context Protocol (MCP) clients, contains a critical vulnerability (CVE-2026-63127) in its OAuth Protected Resource metadata discovery implementation. According to RFC 9728, MCP clients must validate that the \u003ccode\u003eresource\u003c/code\u003e field returned in the metadata document exactly matches the URL used by the client. The \u003ccode\u003ermcp\u003c/code\u003e implementation (versions prior to 2.0.0) lacks both the structure field for \u003ccode\u003eresource\u003c/code\u003e and the necessary validation logic.\u003c/p\u003e\n\u003cp\u003eThis architectural gap allows a malicious MCP server to present a crafted metadata document to an unsuspecting client. By declaring a legitimate resource URL as its own, the malicious server can trick the \u003ccode\u003ermcp\u003c/code\u003e-based client into initiating an OAuth authentication flow with a legitimate authorization server. When the victim completes the authentication, the resulting access token is sent to the malicious server, leading to token exfiltration and complete victim impersonation. The scope includes any application integrating \u003ccode\u003ermcp\u003c/code\u003e that supports OAuth-protected resources.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker deploys a malicious MCP server configured to respond to \u003ccode\u003e.well-known/oauth-protected-resource\u003c/code\u003e discovery requests.\u003c/li\u003e\n\u003cli\u003eAttacker configures the malicious server to return metadata with a \u003ccode\u003eresource\u003c/code\u003e field pointing to a legitimate target (\u003ccode\u003ereal-mcp.com/mcp\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eAttacker lures a victim into connecting their \u003ccode\u003ermcp\u003c/code\u003e-based client to the malicious server.\u003c/li\u003e\n\u003cli\u003eThe client fetches the spoofed metadata document during the discovery phase.\u003c/li\u003e\n\u003cli\u003eThe client parses the metadata and, failing to perform RFC-mandated validation, proceeds to initiate an OAuth flow.\u003c/li\u003e\n\u003cli\u003eThe client redirects the user to the legitimate authorization server associated with the target resource.\u003c/li\u003e\n\u003cli\u003eThe user completes the authentication flow, granting the client an access token meant for the target resource.\u003c/li\u003e\n\u003cli\u003eThe client transmits the authorized token to the malicious MCP server, where the attacker intercepts it for impersonation.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the theft of valid OAuth access tokens. This enables attackers to impersonate the victim on legitimate MCP resource servers. The vulnerability affects all MCP clients built using \u003ccode\u003ermcp\u003c/code\u003e versions prior to 2.0.0. The impact is significant for organizations relying on MCP-based workflows for sensitive data access or system interaction.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for development and security operations:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately identify all applications utilizing the \u003ccode\u003ermcp\u003c/code\u003e crate and upgrade to version 2.0.0 or later to patch CVE-2026-63127.\u003c/li\u003e\n\u003cli\u003eAudit logs for unexpected MCP client connections to unknown or unauthorized discovery endpoints.\u003c/li\u003e\n\u003cli\u003eReview MCP client configuration policies to ensure only verified, trusted MCP servers are allowed for use in production environments.\u003c/li\u003e\n\u003cli\u003ePerform a post-patch review of the \u003ccode\u003ecrates/rmcp/src/transport/auth.rs\u003c/code\u003e file to confirm the inclusion of the \u003ccode\u003eresource\u003c/code\u003e field validation logic as described in the advisory.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-17T01:07:46Z","date_published":"2026-09-17T01:07:46Z","id":"https://feed.craftedsignal.io/briefs/2026-09-rmcp-oauth-vulnerability/","summary":"The rmcp library fails to validate the resource parameter during OAuth metadata discovery per RFC 9728, allowing attackers to spoof metadata and steal access tokens for legitimate MCP servers.","title":"Access Token Theft in rmcp via OAuth Metadata Spoofing","url":"https://feed.craftedsignal.io/briefs/2026-09-rmcp-oauth-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:rmcp_project:rmcp:*:*:*:*:*:rust:*:*","version":"https://jsonfeed.org/version/1.1"}