CVE-2026-63127
Last modified
CVE-2026-63127 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's OAuth implementation in crates/rmcp/src/transport/auth.rs omits the RFC 9728 resource field from ResourceServerMetadata and allows discover_oauth_server_via_resource_metadata to use protected-resource metadata without confirming that the returned resource identifier exactly matches the configured MCP server.
Description
RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's OAuth implementation in crates/rmcp/src/transport/auth.rs omits the RFC 9728 resource field from ResourceServerMetadata and allows discover_oauth_server_via_resource_metadata to use protected-resource metadata without confirming that the returned resource identifier exactly matches the configured MCP server. A malicious MCP server can publish metadata for a different legitimate MCP resource and its authorization server, causing a victim who connects and completes the authorization flow to obtain a legitimate access token that the client subsequently sends to the malicious server. The attacker can capture the token and impersonate the victim against the legitimate MCP resource within the token's granted scopes. This issue is fixed in version 2.0.0.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| modelcontextprotocol | rust-sdk | < 2.0.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-63127?
How severe is CVE-2026-63127?
How do I fix CVE-2026-63127?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-63118MCP Ruby SDK is the official Ruby SDK for Model Context Prot…6.9
- CVE-2026-63119MCP Ruby SDK is the official Ruby SDK for Model Context Prot…6.2
- CVE-2026-6312Insufficient policy enforcement in Passwords in Google Chrom…3.1
- CVE-2026-63123Tina is a headless content management system. Prior to 2.5.2…6.5
- CVE-2026-63125Incus is a system container and virtual machine manager. Pri…9.9
- CVE-2026-63126Wire provides gRPC and protocol buffers for Android, Kotlin,…7.5
- CVE-2026-63128RMCP is an official Rust SDK for the Model Context Protocol.…7.5
- CVE-2026-6313Insufficient policy enforcement in CORS in Google Chrome pri…3.1
- CVE-2026-63131OpenBao is an open source identity-based secrets management …6
- CVE-2026-63132OpenBao is an open source identity-based secrets management …9.2
- CVE-2026-63133Malcolm is a network traffic analysis tool suite. Prior to v…6.5
- CVE-2026-63134Malcolm is a network traffic analysis tool suite. Prior to v…5.4
Are you affected by CVE-2026-63127?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
