Skip to content

MCPP-TRN10: Weak security headers on discovery endpoints

Family Transport
Default severity low
Confidence high
Mode passive (default scan)
Spec revisions all

Why it matters

Metadata documents steer clients to authorization servers. They should not be MIME-sniffable, and must never be readable cross-origin with credentials.

Remediation

Serve metadata as application/json with X-Content-Type-Options: nosniff. Public CORS (*) is fine for metadata, but never combine it with Access-Control-Allow-Credentials: true.

References

Suppressing

# .mcp-posture-ignore
[[ignore]]
check = "MCPP-TRN10"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31