GHSA-C9XM-49CP-XCR9: Server-Side Request Forgery in rmcp OAuth Client
Vulnerability ID: GHSA-C9XM-49CP-XCR9
CVSS Score: 6.3
Published: 2026-10-02
A Server-Side Request Forgery (SSRF) vulnerability exists in the rmcp OAuth client, which is part of the Model Context Protocol (MCP) Rust SDK. The vulnerability arises from insecure processing of the resource_metadata parameter in WWW-Authenticate headers returned by a malicious or compromised MCP server. The client parses and fetches absolute URLs from this header without validation of scheme, origin, or network routing, allowing remote attackers to initiate HTTP GET requests to local network interfaces, RFC 1918 private subnets, or cloud metadata endpoints.
TL;DR
The rmcp OAuth client blindly fetches absolute URLs from the resource_metadata parameter in the WWW-Authenticate header of an MCP server response. Attackers can exploit this to perform Server-Side Request Forgery (SSRF), targeting loopback networks, private IP spaces, or cloud metadata endpoints like 169.254.169.254.
Technical Details
- CWE ID: CWE-918
- Attack Vector: Network
- CVSS Score: 6.3
- Exploit Status: poc
- CISA KEV Status: Not Listed
- Impact: Information Disclosure / Server-Side Request Forgery
Affected Systems
- Rust applications using the rmcp crate inside the Model Context Protocol SDK
-
rmcp: < 2.0.0 (Fixed in:
2.0.0)
Code Analysis
Commit: eb435c6
Implement same-origin restrictions, loopback filters, and manual redirect validation for rmcp OAuth client operations.
Exploit Details
- GitHub Security Advisory: Proof of concept challenge-response transaction is detailed in the official advisory text.
Mitigation Strategies
- Upgrade the rmcp dependency in Cargo.toml to version 2.0.0 or higher.
- Enforce network-level egress restrictions to block outbound connections to loopback interfaces, private networks, and link-local cloud endpoints.
- Restrict the list of connected MCP servers to a strict allowlist of known trusted endpoints.
Remediation Steps:
- Open the Cargo.toml project configuration file.
- Locate the rmcp dependency declaration.
- Update the version string to '2.0.0' or higher.
- Execute 'cargo update' to apply the dependency version change.
- Configure cloud network firewall rules to block egress to metadata IP 169.254.169.254.
References
Read the full report for GHSA-C9XM-49CP-XCR9 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)