rmcp is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
74
High Risk
The rmcp Streamable HTTP client transport builds its default HTTP client without disabling automatic redirect following. Caller-supplied custom headers, including secret authentication headers such as X-API-Key, are not marked sensitive, so they are forwarded to cross-origin redirect targets while only standard credential headers are stripped. A compromised or malicious MCP server that returns a cross-origin redirect can capture these credentials from the victim client. The fix disables automatic redirect following so custom headers are no longer leaked to redirect destinations.
You are affected if you are using a version that falls within the vulnerable range and you use the StreamableHttpClientTransport with secret custom headers configured via custom_headers.
rmcp is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.0.1 - 2.0.0.
Upgrade the rmcp library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant