OAuth Implementation Flaw in RMCP Rust SDK Affects Model Context Protocol
CVE-2026-63127

8.2HIGH

Key Information:

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-63127?

The RMCP Rust SDK's OAuth implementation before version 2.0.0 contains a significant vulnerability. It fails to validate that the resource identifier used in the authorization flow matches the configured MCP server, allowing attackers to exploit this oversight. A malicious MCP server can deliver counterfeit metadata for a different legitimate resource, enabling an unsuspecting client to unwittingly connect and complete the OAuth flow. This results in the client receiving a legitimate access token, which can then be captured by the attacker. Consequently, the attacker is able to impersonate the user in interactions with the legitimate resource within the scopes granted by the token. Version 2.0.0 rectifies this issue, making it essential for users to update immediately.

Affected Version(s)

rust-sdk < 2.0.0

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.