Skip to content

feat: AVE-2026-00077 -- cross-origin tool/resource declaration in a single MCP server manifest - #168

Merged
chaksaray merged 1 commit into
developfrom
ave-00077-cross-origin-mcp
Aug 9, 2026
Merged

chaksaray merged 1 commit into
developfrom
ave-00077-cross-origin-mcp

Conversation

@chaksaray

Copy link
Copy Markdown
Contributor

Closes #149.

Summary

  • A single MCP server's own manifest declares tools/resources spanning multiple unrelated root domains (or mixed http/https schemes). Everything in one server's manifest is typically treated as sharing one trust boundary once the server is trusted, so a minority-domain tool/resource can inject, override, or hijack context intended for the trusted majority origin within the same session -- no false identity claim required.
  • Distinctness confirmed via real field comparison (Step 2 of researcher-process.md), not label matching: AVE-2026-00001's mechanism is a single external source's fetched content changing at read time; AVE-2026-00017 requires a false identity claim. Here every origin is honestly declared -- the risk is structural domain diversity. Corpus-wide keyword sweep (cross-origin, multi-domain, root domain, mixed scheme, etc.) confirmed clean.
  • Primary source read directly, not taken from the issue's own characterization: highflame-ai/ramparts src/security/cross_origin_scanner.rs (extracts every declared URL from all tools/resources, groups by root domain, flags unique_root_domains.len() > 1 and mixed schemes) and rules/pre/cross_origin_escalation.yar (doc-comment quote verified verbatim).
  • researcher credits the file's actual author (git log --diff-filter=A), not a generic "security team" name -- caught the same class of mistake this project corrected earlier (fix: researcher field attribution rule and worked example #154/fix: resolve the 10 records flagged by the researcher/disclosure check #158).
  • owasp_mcp corrected from the issue's own proposed MCP03 (Tool Poisoning, doesn't fit -- no poisoned tool description here) to MCP07 + MCP10, verified against OWASP's real 2025 MCP Top 10 category list.
  • mitre_atlas empty array independently re-verified against the full current ATLAS.yaml technique set (170 techniques), not accepted from the issue's own "checked, no fit" claim at face value.
  • nist_ai_rmf (MAP-4.2) verified against NIST's own AIRC playbook text -- "Internal risk controls for components of the AI system including third-party AI technologies are identified and documented."
  • Severity MEDIUM, AIVSS 4.8 (cvss_base 8.3, aars 4.5, thm 0.75 -- theoretical/architectural, no disclosed CVE, matching the issue's own honest framing).

Test plan

  • python3 scripts/validate_records.py -- 77/77 valid
  • python3 scripts/check_fixtures.py
  • python3 scripts/validate_crosswalks.py -- 6/6 valid
  • pytest tests/ -x -q -- 309 passed
  • node scripts/build-records.js -- dist regenerated, frozen v1.1.0 snapshot untouched
  • README record count (badge, Stats table, collapsible index) and CHANGELOG updated

… single MCP server manifest

A single MCP server's own manifest declares tools and/or resources
whose URLs span multiple unrelated root domains, or mix http/https
schemes. Because everything in one server's manifest is typically
treated as sharing one trust boundary once the server is trusted, a
minority-domain tool or resource can inject, override, or hijack
context intended for the trusted majority origin, within the same
session -- no false identity claim required.

Confirmed genuinely distinct via real field comparison, not label
matching: AVE-2026-00001 is a single external source's content
changing at fetch time; AVE-2026-00017 requires a false identity
claim. Here every origin is honestly declared -- the risk is
structural domain diversity, not deception.

Primary source verified directly against Ramparts' actual code
(src/security/cross_origin_scanner.rs, rules/pre/cross_origin_escalation.yar),
not just the originating issue's characterization of it. researcher
field credits the file's actual author (git blame), not a generic
team name. owasp_mcp corrected from the issue's own MCP03 proposal to
MCP07+MCP10 after checking the real 2025 OWASP MCP Top 10 list --
MCP03 (Tool Poisoning) doesn't fit a mechanism with no poisoned tool
description. mitre_atlas empty array independently re-verified against
the full current ATLAS.yaml technique set, not accepted from the issue
at face value. nist_ai_rmf (MAP-4.2) verified against NIST's own AIRC
playbook text.

Closes #149.
@chaksaray
chaksaray merged commit 4f9e454 into develop Aug 9, 2026
6 checks passed
@chaksaray
chaksaray deleted the ave-00077-cross-origin-mcp branch August 9, 2026 23:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant