Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-69196

Опубликовано: 16 мар. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly respect the resource parameter submitted by the client in the authorization and token request. Instead of issuing the token explicitly for the MCP server, the token is issued for the base_url passed to the OAuthProxy during initialization. This issue has been patched 2.14.2.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:jlowin:fastmcp:*:*:*:*:*:*:*:*
Версия до 2.14.2 (исключая)

EPSS

Процентиль: 2%
0.00013
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 7.4
redhat
18 дней назад

FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly respect the resource parameter submitted by the client in the authorization and token request. Instead of issuing the token explicitly for the MCP server, the token is issued for the base_url passed to the OAuthProxy during initialization. This issue has been patched 2.14.2.

github
18 дней назад

FastMCP OAuth Proxy token reuse across MCP servers

EPSS

Процентиль: 2%
0.00013
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863