Skip to content

Client accepts tool responses with missing or invalid jsonrpc version #589

Description

@anilloutombam

Observed behavior

With mcp 1.6.1, MCP::Client#call_tool returns normally when the server's response omits jsonrpc or sets it to "1.0". Both variants were accepted in three independent runs over stdio and three over Streamable HTTP, using the legacy 2025-11-25 lifecycle.

The response keeps the matching request ID and valid tool result; only the jsonrpc field is changed.

Expected behavior

Reject these responses as invalid JSON-RPC 2.0 envelopes rather than return a successful tool result. JSON-RPC 2.0 section 5 requires the response's jsonrpc value to be exactly "2.0".

Reproduction

Requires Ruby, the mcp gem at 1.6.1, and Node.js/npm. Save this as repro.rb, then run ruby repro.rb:

require "json"
gem "mcp", "1.6.1"
require "mcp"

%w[missing-jsonrpc invalid-jsonrpc-version].each do |variant|
  adapter = MCP::Client::Stdio.new(
    command: "npx",
    args: ["-y", "mcp-failure-lab@0.12.0", "serve"],
    read_timeout: 5,
  )
  begin
    client = MCP::Client.new(transport: adapter)
    client.connect(
      client_info: { name: "jsonrpc-repro", version: "1.0.0" },
      protocol_version: "2025-11-25",
      mode: :legacy,
    )
    response = client.call_tool(
      name: "malformed_message",
      arguments: { variant: variant },
    )
    puts "#{variant}: accepted #{JSON.generate(response)}"
  ensure
    adapter.close
  end
end

malformed_message changes the response envelope for that call: missing-jsonrpc removes the field, and invalid-jsonrpc-version sets it to "1.0". Initialization uses valid responses.

Environment and evidence

The separate variant containing both result and error raised an error; a subsequent ping using the same client succeeded. This report is limited to the two jsonrpc variants above. Modern lifecycle behavior was not tested.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions