mcp-server-fetch: `fetch` prompt returns JSON-RPC error code 0 with the raw exception text for an invalid URL
Los mantenedores suelen responder en 1 día
Evaluación
- Dificultad
- 2/5
- Tiempo estimado
- 1-3 horas
- Aptitud para principiantes
- 78/100
Línea de trabajo
Comienza en server.py, en las líneas 127 y 262-288, y después reproduce la solicitud prompts/get con la URL mal formada mostrada en el issue. Compara el manejo de prompts con la validación del modelo Fetch utilizada por la herramienta y verifica que una entrada no válida devuelva JSON-RPC -32602 con un mensaje claro, mientras que las URL válidas sigan devolviendo el contenido de la página.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Describe the bug
The fetch tool validates url through the Fetch model, so a malformed URL comes back as a normal isError: true result. The fetch prompt passes arguments["url"] straight to fetch_url (server.py:262-265) and catches only McpError (server.py:267). fetch_url converts only httpx.HTTPError (server.py:127), and httpx.InvalidURL is not an HTTPError, so it escapes both handlers. With raise_exceptions=False (server.py:288), the SDK's low-level server then answers with a JSON-RPC error whose code is 0 and whose message is the raw exception text.
To Reproduce
mcp-server-fetch 0.6.3 (commit f46d957), mcp 1.29.0 (as in uv.lock), Python 3.14, Windows 11. After initialize, send over stdio:
{"jsonrpc": "2.0", "id": 3, "method": "prompts/get", "params": {"name": "fetch", "arguments": {"url": "http://[::1"}}}
Response:
{"jsonrpc": "2.0", "id": 3, "error": {"code": 0, "message": "Invalid port: ':1'"}}
The same URL through the tool is handled cleanly:
{"jsonrpc": "2.0", "id": 4, "method": "tools/call", "params": {"name": "fetch", "arguments": {"url": "http://[::1"}}}
isError: true — "1 validation error for Fetch\nurl\n Input should be a valid URL, invalid IPv6 address ..."
Expected behavior
An invalid prompt argument should produce a proper parameter error (-32602, INVALID_PARAMS) with a clear message, consistent with the tool. Code 0 is the SDK's generic fallback for unhandled exceptions, so a client can't tell a bad argument from a server fault.
Suggested fix
Validate the prompt's url the same way the tool does before fetching:
url = arguments["url"] # current code; replace with:
try:
url = str(Fetch(url=arguments["url"]).url)
except ValueError as e:
raise McpError(ErrorData(code=INVALID_PARAMS, message=str(e)))
With this change, the request above returns -32602 with the validation message, and a valid URL still returns the page content (checked locally).
Additional context
Related: #3359 / #3515 (malformed input handling). I found this while testing a static checker for MCP error handling, then reproduced it by hand with a raw JSON-RPC client (no MCP client library involved). Happy to open a PR with this change if that's useful.
- Lenguaje dominante
- TypeScript
- Estrellas
- 91k
- Forks
- 11.8k
- Merge medio
- 6 h 47 min
- PR fusionados (30 d)
- 74
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Tiene una plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de modelcontextprotocol/servers
-
CLAUDE.md: tool-naming rule (kebab-case) disagrees with filesystem and memory serversPosiblemente ocupada @liang0417 la tomó hace 7 días. Abierto
Dificultad 1/5 Menos de una hora Aptitud para principiantes 92/100
modelcontextprotocol/servers#4892 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Filesystem README recommends deprecated MCP Roots protocol for restricting directory accessPosiblemente ocupada @its-amann la tomó hace 12 días. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
modelcontextprotocol/servers#4844 ·
Los mantenedores suelen responder en 1 día
-
Docs: `fetch` installs npm packages during a tool call, which is worth stating for deploymentsPosiblemente ocupada @teddiesloco la tomó hace 16 días. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
modelcontextprotocol/servers#4830 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Docs: tool descriptions for browser-embedding servers do not mention the browser's own background trafficPosiblemente ocupada @AbhiPra24 la tomó hace 12 días. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
modelcontextprotocol/servers#4829 ·
Los mantenedores suelen responder en 1 día
-
README gate confirmation command can be used by any commenter, bypassing the "readme: pending" gatePosiblemente ocupada @FanouZeng-TT la tomó hace 21 días. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
modelcontextprotocol/servers#4796 ·
Los mantenedores suelen responder en 1 día
Todos los issues de modelcontextprotocol/servers
Issues similares
-
triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
github/docs#46222 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
agent-ready area: config area: skills type: chore upstream: brain-kit
Dificultad 1/5 Menos de una hora Aptitud para principiantes 95/100
-
enhancement priority:low ready-for-dev
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
Los mantenedores suelen responder en 1 día
-
bug escritorio mapa
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
marcosferr/reporte-ciudadano#4 · 1 comentario ·
-
area: material/sort gemini-triaged needs triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
angular/components#33933 ·
Los mantenedores suelen responder en 1 día