Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions .jules/sentinel.md
Original file line number Diff line number Diff line change
Expand Up @@ -126,3 +126,8 @@ Error messages should never include raw values from sensitive sources like envir
**Prevention:**
1. Avoid including raw values in error messages when the source is potentially sensitive (env vars, auth headers).
2. Use generic error messages for validation failures of sensitive data.

## 2024-05-20 - [Information Leakage in JSON-RPC Handlers]
**Vulnerability:** The MCP Server's JSON-RPC handlers for `prompts/get`, `resources/read`, and `completion/complete` were directly passing internal error messages `(error as Error).message` to the client. This exposed internal error details and potentially sensitive stack traces.
**Learning:** Even when handling non-tool execution endpoints, error messages must be sanitized before being sent to external clients to prevent information leakage.
**Prevention:** Always use the `this.formatErrorForClient(error, correlationId)` method in conjunction with generating a `correlationId` to ensure client-facing errors are safely generic (e.g., `Internal error`), while securely logging the detailed internal error using `this.logger.error`.
4 changes: 2 additions & 2 deletions src/mcp/mcp-server-apps.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -277,11 +277,11 @@ describe('MCPServer apps resources', () => {

expect(invalidReadResponse.error).toEqual({
code: -32602,
message: 'resources/read requires string parameter "uri"',
message: expect.stringMatching(/^Validation error: resources\/read requires string parameter "uri" \(correlation ID: .*\)$/),
});
expect(invalidCompletionResponse.error).toEqual({
code: -32602,
message: 'completion/complete requires a resource ref',
message: expect.stringMatching(/^Validation error: completion\/complete requires a resource ref \(correlation ID: .*\)$/),
});
});

Expand Down
12 changes: 9 additions & 3 deletions src/mcp/mcp-server.ts
Original file line number Diff line number Diff line change
Expand Up @@ -2281,12 +2281,14 @@ export class MCPServer {
code = -32601;
}

const correlationId = generateCorrelationId();
this.logger.error('prompts/get handler error', error as Error, { correlationId, sessionId });
return {
jsonrpc: '2.0',
id: req.id,
error: {
code,
message: (error as Error).message,
message: this.formatErrorForClient(error, correlationId),
},
};
}
Expand Down Expand Up @@ -2324,12 +2326,14 @@ export class MCPServer {
result: await this.readResource(params.uri, sessionId, profileId),
};
} catch (error) {
const correlationId = generateCorrelationId();
this.logger.error('resources/read handler error', error as Error, { correlationId, sessionId });
return {
jsonrpc: '2.0',
id: req.id,
error: {
code: error instanceof ValidationError ? -32602 : -32601,
message: (error as Error).message,
message: this.formatErrorForClient(error, correlationId),
},
};
}
Expand All @@ -2343,12 +2347,14 @@ export class MCPServer {
result: await this.completeResourceArgument(req as CompleteRequest, sessionId, profileId),
};
} catch (error) {
const correlationId = generateCorrelationId();
this.logger.error('completion/complete handler error', error as Error, { correlationId, sessionId });
return {
jsonrpc: '2.0',
id: req.id,
error: {
code: error instanceof ValidationError ? -32602 : -32601,
message: (error as Error).message,
message: this.formatErrorForClient(error, correlationId),
},
};
}
Expand Down
Loading