Skip to content

MCP Client x-mcp-header Value-Encoding Failure (Model-Controlled HTTP Header Injection)

mcp-client-header-value-encoding is a high severity check in the ai category, written in python. Its source is templates/ai/mcp/client-conformance/mcp-client-header-value-encoding.py in cert-x-gen-templates.

ACTIVE check. The MCP 2026-07-28 revision (SEP-2243) lets a tool PARAMETER be marked x-mcp-header, so a value the model chose is placed by the CLIENT into the outgoing HTTP header block. The spec puts the value-encoding MUST on the client. This drives an MCP client against a synthetic server whose tool schema hands it a value carrying CR LF and a decoy Authorization header, then reads the RAW BYTES the client put on the wire. Extra header lines, or unencoded control characters in the value, confirm client-side header injection.

Field Value
Id mcp-client-header-value-encoding
Severity high
Language python
Category ai
Author Bugb Research
Template version 1.0.0
Confidence 93
CVSS 7.5
Weakness CWE-93, CWE-113
Tags mcp, ai, agent, mcp-client, mcp-client-conformance, agent-posture, header-injection, x-mcp-header, sep-2243, crlf-injection, request-splitting, behavioural, active, intrusive, cwe-93, cwe-113
Target kind cli
Oracle property

Declared in the header. cxg parses @references and then discards it, and nothing at scan time reads it, so this is the only place the links a template cites are surfaced.

To see what the copy on your machine says about itself, and to confirm it is installed at all:

Terminal window
cxg template info mcp-client-header-value-encoding

The id it prints is the one to pass anywhere a template is selected. See cxg template for the rest of the subcommand, Scan a target for running a scan, and A match is not a finding for how to read what comes back.