feat: AVE-2026-00077 -- cross-origin tool/resource declaration in a single MCP server manifest - #168
Merged
Merged
Conversation
… single MCP server manifest A single MCP server's own manifest declares tools and/or resources whose URLs span multiple unrelated root domains, or mix http/https schemes. Because everything in one server's manifest is typically treated as sharing one trust boundary once the server is trusted, a minority-domain tool or resource can inject, override, or hijack context intended for the trusted majority origin, within the same session -- no false identity claim required. Confirmed genuinely distinct via real field comparison, not label matching: AVE-2026-00001 is a single external source's content changing at fetch time; AVE-2026-00017 requires a false identity claim. Here every origin is honestly declared -- the risk is structural domain diversity, not deception. Primary source verified directly against Ramparts' actual code (src/security/cross_origin_scanner.rs, rules/pre/cross_origin_escalation.yar), not just the originating issue's characterization of it. researcher field credits the file's actual author (git blame), not a generic team name. owasp_mcp corrected from the issue's own MCP03 proposal to MCP07+MCP10 after checking the real 2025 OWASP MCP Top 10 list -- MCP03 (Tool Poisoning) doesn't fit a mechanism with no poisoned tool description. mitre_atlas empty array independently re-verified against the full current ATLAS.yaml technique set, not accepted from the issue at face value. nist_ai_rmf (MAP-4.2) verified against NIST's own AIRC playbook text. Closes #149.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #149.
Summary
researcher-process.md), not label matching:AVE-2026-00001's mechanism is a single external source's fetched content changing at read time;AVE-2026-00017requires a false identity claim. Here every origin is honestly declared -- the risk is structural domain diversity. Corpus-wide keyword sweep (cross-origin, multi-domain, root domain, mixed scheme, etc.) confirmed clean.highflame-ai/rampartssrc/security/cross_origin_scanner.rs(extracts every declared URL from all tools/resources, groups by root domain, flagsunique_root_domains.len() > 1and mixed schemes) andrules/pre/cross_origin_escalation.yar(doc-comment quote verified verbatim).researchercredits the file's actual author (git log --diff-filter=A), not a generic "security team" name -- caught the same class of mistake this project corrected earlier (fix: researcher field attribution rule and worked example #154/fix: resolve the 10 records flagged by the researcher/disclosure check #158).owasp_mcpcorrected from the issue's own proposed MCP03 (Tool Poisoning, doesn't fit -- no poisoned tool description here) to MCP07 + MCP10, verified against OWASP's real 2025 MCP Top 10 category list.mitre_atlasempty array independently re-verified against the full currentATLAS.yamltechnique set (170 techniques), not accepted from the issue's own "checked, no fit" claim at face value.nist_ai_rmf(MAP-4.2) verified against NIST's own AIRC playbook text -- "Internal risk controls for components of the AI system including third-party AI technologies are identified and documented."cvss_base8.3,aars4.5,thm0.75 -- theoretical/architectural, no disclosed CVE, matching the issue's own honest framing).Test plan
python3 scripts/validate_records.py-- 77/77 validpython3 scripts/check_fixtures.pypython3 scripts/validate_crosswalks.py-- 6/6 validpytest tests/ -x -q-- 309 passednode scripts/build-records.js-- dist regenerated, frozen v1.1.0 snapshot untouched