THREAT OPS › Threat News › [GHSA] GHSA-33f5-2c5q-wgwj (high) — RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery
[GHSA] GHSA-33f5-2c5q-wgwj (high) — RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery
GHSA-33f5-2c5q-wgwj Severity: high CVE: CVE-2026-63127
RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery
### Summary The `rmcp` library does not validate the `resource` parameter in OAuth Protected Resource metadata (RFC 9728), allowing a malicious MCP server to redirect OAuth flows to a legitimate authorization server and steal the resulting access tokens.
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-63127cve
- fake-mcp.comdomain
- real-mcp.comdomain
Original source: https://github.com/advisories/GHSA-33f5-2c5q-wgwj