Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-69196

Опубликовано: 16 мар. 2026
Источник: nvd
CVSS3: 6.5
CVSS3: 7.4
EPSS Низкий

Описание

FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly respect the resource parameter submitted by the client in the authorization and token request. Instead of issuing the token explicitly for the MCP server, the token is issued for the base_url passed to the OAuthProxy during initialization. This issue has been patched 2.14.2.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:jlowin:fastmcp:*:*:*:*:*:*:*:*
Версия до 2.14.2 (исключая)

EPSS

Процентиль: 29%
0.00358
Низкий

6.5 Medium

CVSS3

7.4 High

CVSS3

Дефекты

CWE-863
CWE-1220

Связанные уязвимости

CVSS3: 7.4
redhat
5 месяцев назад

FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly respect the resource parameter submitted by the client in the authorization and token request. Instead of issuing the token explicitly for the MCP server, the token is issued for the base_url passed to the OAuthProxy during initialization. This issue has been patched 2.14.2.

github
5 месяцев назад

FastMCP OAuth Proxy token reuse across MCP servers

EPSS

Процентиль: 29%
0.00358
Низкий

6.5 Medium

CVSS3

7.4 High

CVSS3

Дефекты

CWE-863
CWE-1220