mcp-streamable-http-exposure: MCP Streamable HTTP Server - Unauthenticated Initialize

2026-09-28 Unknown PoC Public

Description

Detects a Model Context Protocol server exposing the Streamable HTTP transport that completes the JSON-RPC 2.0 `initialize` handshake without any credentials. The MCP lifecycle requires `initialize` to be the first interaction on a connection, and a spec-compliant server answers it with an InitializeResult carrying `protocolVersion`, `capabilities` and `serverInfo`. Receiving that result from an unauthenticated POST shows the endpoint performs no authorization before entering the operation phase, so any caller can go on to enumerate and invoke the tools, resources and prompts the server exposes.

PoC

id: mcp-streamable-http-exposure

info:
  name: MCP Streamable HTTP Server - Unauthenticated Initialize
  author: DevamShah
  severity: unknown
  description: |
    Detects a Model Context Protocol server exposing the Streamable HTTP transport that completes the JSON-RPC 2.0 `initialize` handshake without any credentials. The MCP lifecycle requires `initialize` to be the first interaction on a connection, and a spec-compliant server answers it with an InitializeResult carrying `protocolVersion`, `capabilities` and `serverInfo`. Receiving that result from an unauthenticated POST shows the endpoint performs no authorization before entering the operation phase, so any caller can go on to enumerate and invoke the tools, resources and prompts the server exposes.
  impact: |
    An unauthenticated client can negotiate a session and then reach every capability advertised in the handshake, which commonly includes filesystem access, database queries, cloud API calls and shell execution depending on what the operator wired into the server.
  remediation: |
    Require authentication on the MCP endpoint, validate the Origin header to prevent DNS rebinding, and bind local servers to 127.0.0.1 instead of 0.0.0.0.
  reference:
    - https://modelcontextprotocol.io/specification/2025-06-18/basic/transports
    - https://modelcontextprotocol.io/specification/2025-06-18/basic/lifecycle
  metadata:
    verified: true
    max-request: 3
    fofa-query: header="mcp-session-id"
  tags: mcp,jsonrpc,exposure,api,ai,llm,unauth

http:
  - raw:
      - |
        POST {{path}} HTTP/1.1
        Host: {{Hostname}}
        Content-Type: application/json
        Accept: application/json, text/event-stream

        {"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2024-11-05","capabilities":{},"clientInfo":{"name":"nuclei","version":"1.0"}}}

    payloads:
      path:
        - "/mcp"
        - "/mcp/"
        - "/api/mcp"

    stop-at-first-match: true

    matchers-condition: and
    matchers:
      - type: regex
        part: body
        regex:
          - '"protocolVersion"\s*:\s*"\d{4}-\d{2}-\d{2}"'

      - type: dsl
        dsl:
          - 'contains_all(body, "serverInfo", "capabilities", "jsonrpc")'
          - 'contains(content_type, "application/json") || contains(content_type, "text/event-stream")'
          - 'status_code == 200'
        condition: and

    extractors:
      - type: regex
        name: protocol_version
        part: body
        group: 1
        regex:
          - '"protocolVersion"\s*:\s*"(\d{4}-\d{2}-\d{2})"'

      - type: regex
        name: server
        part: body
        group: 1
        regex:
          - '"serverInfo"\s*:\s*\{[^}]*?"name"\s*:\s*"([^"]+)"'
# digest: 4b0a00483046022100a134310850288b2d9913cccb71483db29218ba16fed52d341248539037c8c0f602210081abb1b4f249de2219bf9dd90732d38a33c5f356f9613f6c7c74cb9abb936011:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.