Security Flaw in Model Context Protocol Rust SDK Allows Token Replay Attacks
CVE-2026-64684
6.8MEDIUM
What is CVE-2026-64684?
The Model Context Protocol Rust SDK prior to version 2.1.0 contains a vulnerability in its StreamableHttpClientTransport, which improperly handles custom headers when following cross-origin redirects. An attacker can exploit this flaw by redirecting requests from a malicious endpoint that causes the SDK to replay sensitive tokens or API keys, potentially allowing unauthorized access to resources. The vulnerability has been addressed in version 2.1.0 to prevent this security risk.
Affected Version(s)
rust-sdk < 2.1.0
