Skip to content

Add advisory for rmcp DNS rebinding#2998

Open
DaleSeo wants to merge 1 commit into
rustsec:mainfrom
DaleSeo:add-rmcp-advisory
Open

Add advisory for rmcp DNS rebinding#2998
DaleSeo wants to merge 1 commit into
rustsec:mainfrom
DaleSeo:add-rmcp-advisory

Conversation

@DaleSeo

@DaleSeo DaleSeo commented Jun 26, 2026

Copy link
Copy Markdown

Affected crate(s)

  • rmcp (13,797,440 total downloads; 7,472,054 recent downloads per crates.io)

Links to upstream issue(s) or PR(s)

Severity

High. A malicious public website could use DNS rebinding to send requests to a locally running rmcp Streamable HTTP server, allowing it to enumerate and invoke exposed MCP tools and access resources or prompts available through that server. The upstream GHSA uses CVSS 3.1 score 8.8.

Checklist

  • Advisory filename(s) starts with RUSTSEC-0000-0000 as the ID
  • date field is set to the public disclosure date
  • Contains a concise and descriptive title after advisory metadata
  • Asked maintainer(s) if publishing an advisory is appropriate

Testing

  • Added the advisory under crates/rmcp/RUSTSEC-0000-0000.md using the RustSec template.
  • Ran rustsec-admin lint; it currently stops on an existing pnet advisory before reaching this new file (crates.io package name does not match package name in advisory for pnet in RUSTSEC-2019-0037).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant