Skip to content

Promotion validation permits client-derived values to target reserved x-mcp-* and x-a2a-* headers #1148

Description

@leseb

Clawpatch finding

Evidence

  • apis/src/promotion.rs:172-182 (is_unsafe_promotion_target_lowercase)
  • apis/src/anthropic/messages_format/config.rs:145-153 (validate_anthropic_format_headers)
  • apis/src/anthropic/messages_format/mod.rs:244-269 (promote_headers)

Description

Configuration such as headers.model: x-mcp-method or headers.format: x-a2a-family passes validation, after which an untrusted request body supplies the reserved internal header value. Because body promotions occur inside the request-processing lifecycle, this bypasses the boundary that rejects client-supplied reserved headers and can influence later MCP or A2A routing/classification logic.

Reproduction

Configure anthropic_messages_format with headers.model: x-mcp-method, then submit a Messages body whose model is tools/call. Configuration succeeds and the filter emits x-mcp-method: tools/call from client-controlled JSON instead of rejecting the reserved target.

Recommendation

Treat x-mcp-* and x-a2a-* as unsafe promotion targets alongside x-praxis-*, except for narrowly documented dedicated headers if any legitimate producer requires them.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    Projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions