FastMCP OAuth Proxy token reuse across MCP servers
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.4epss 0.4%
probabilidad de explotación
0.4%top 71% de las CVE
explotación observada
noninguna fuente lo reporta
FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly respect the resource parameter submitted by the client in the authorization and token request. Instead of issuing the token explicitly for the MCP server, the token is issued for the base_url passed to the OAuthProxy during initialization. This issue has been patched 2.14.2.
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Productos afectados
jlowin · fastmcpReferencias
https://access.redhat.com/errata/RHSA-2026:36350https://access.redhat.com/security/cve/CVE-2025-69196https://bugzilla.redhat.com/show_bug.cgi?id=2448179https://github.com/PrefectHQ/fastmcp/security/advisories/GHSA-5h2m-4q8j-pqpjhttps://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69196.json