mcp-streamable-http-exposure: MCP Streamable HTTP Server - Unauthenticated Initialize
2026-09-28UnknownPoC Public
Description
Detects a Model Context Protocol server exposing the Streamable HTTP transport that completes the JSON-RPC 2.0 `initialize` handshake without any credentials. The MCP lifecycle requires `initialize` to be the first interaction on a connection, and a spec-compliant server answers it with an InitializeResult carrying `protocolVersion`, `capabilities` and `serverInfo`. Receiving that result from an unauthenticated POST shows the endpoint performs no authorization before entering the operation phase, so any caller can go on to enumerate and invoke the tools, resources and prompts the server exposes.
PoC
id: mcp-streamable-http-exposure
info:
name: MCP Streamable HTTP Server - Unauthenticated Initialize
author: DevamShah
severity: unknown
description: |
Detects a Model Context Protocol server exposing the Streamable HTTP transport that completes the JSON-RPC 2.0 `initialize` handshake without any credentials. The MCP lifecycle requires `initialize` to be the first interaction on a connection, and a spec-compliant server answers it with an InitializeResult carrying `protocolVersion`, `capabilities` and `serverInfo`. Receiving that result from an unauthenticated POST shows the endpoint performs no authorization before entering the operation phase, so any caller can go on to enumerate and invoke the tools, resources and prompts the server exposes.
impact: |
An unauthenticated client can negotiate a session and then reach every capability advertised in the handshake, which commonly includes filesystem access, database queries, cloud API calls and shell execution depending on what the operator wired into the server.
remediation: |
Require authentication on the MCP endpoint, validate the Origin header to prevent DNS rebinding, and bind local servers to 127.0.0.1 instead of 0.0.0.0.
reference:
- https://modelcontextprotocol.io/specification/2025-06-18/basic/transports
- https://modelcontextprotocol.io/specification/2025-06-18/basic/lifecycle
metadata:
verified: true
max-request: 3
fofa-query: header="mcp-session-id"
tags: mcp,jsonrpc,exposure,api,ai,llm,unauth
http:
- raw:
- |
POST {{path}} HTTP/1.1
Host: {{Hostname}}
Content-Type: application/json
Accept: application/json, text/event-stream
{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2024-11-05","capabilities":{},"clientInfo":{"name":"nuclei","version":"1.0"}}}
payloads:
path:
- "/mcp"
- "/mcp/"
- "/api/mcp"
stop-at-first-match: true
matchers-condition: and
matchers:
- type: regex
part: body
regex:
- '"protocolVersion"\s*:\s*"\d{4}-\d{2}-\d{2}"'
- type: dsl
dsl:
- 'contains_all(body, "serverInfo", "capabilities", "jsonrpc")'
- 'contains(content_type, "application/json") || contains(content_type, "text/event-stream")'
- 'status_code == 200'
condition: and
extractors:
- type: regex
name: protocol_version
part: body
group: 1
regex:
- '"protocolVersion"\s*:\s*"(\d{4}-\d{2}-\d{2})"'
- type: regex
name: server
part: body
group: 1
regex:
- '"serverInfo"\s*:\s*\{[^}]*?"name"\s*:\s*"([^"]+)"'
# digest: 4b0a00483046022100a134310850288b2d9913cccb71483db29218ba16fed52d341248539037c8c0f602210081abb1b4f249de2219bf9dd90732d38a33c5f356f9613f6c7c74cb9abb936011:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.