THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-33f5-2c5q-wgwj (high) — RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery

[GHSA] GHSA-33f5-2c5q-wgwj (high) — RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery

highgithub_advisoriesPublished 2026-09-16

GHSA-33f5-2c5q-wgwj Severity: high CVE: CVE-2026-63127

RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery

### Summary The `rmcp` library does not validate the `resource` parameter in OAuth Protected Resource metadata (RFC 9728), allowing a malicious MCP server to redirect OAuth flows to a legitimate authorization server and steal the resulting access tokens.

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-33f5-2c5q-wgwj