Security Flaw in Model Context Protocol Rust SDK Allows Token Replay Attacks
CVE-2026-64684

6.8MEDIUM

Key Information:

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-64684?

The Model Context Protocol Rust SDK prior to version 2.1.0 contains a vulnerability in its StreamableHttpClientTransport, which improperly handles custom headers when following cross-origin redirects. An attacker can exploit this flaw by redirecting requests from a malicious endpoint that causes the SDK to replay sensitive tokens or API keys, potentially allowing unauthorized access to resources. The vulnerability has been addressed in version 2.1.0 to prevent this security risk.

Affected Version(s)

rust-sdk < 2.1.0

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.