{"data":{"id":"9c9a1e47-24fd-45e2-a3a2-36ed67614aa5","title":"GHSA-5h2m-4q8j-pqpj: FastMCP OAuth Proxy token reuse across MCP servers","summary":"The FastMCP OAuth Proxy ignores the client-supplied `resource` parameter in authorization and token requests and issues tokens for the `base_url` set at initialization instead. Because the tokens carry no resource information, a benign MCP server cannot verify that a token was issued for it. An attacker can run a malicious MCP server that advertises the benign proxy as its authorization server, capture the token from a victim's OAuth flow, and replay it against other MCP servers that share that authorization server.","solution":"To mitigate this vulnerability, it is recommended to issue tokens specifically for the MCP server submitted in the authorization URL's `resource` GET parameter. In this way, the receiving MCP server will be able to properly verify that the token was indeed issued for it, allowing it to reject tokens stolen by an attack like the one demonstrated above.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-5h2m-4q8j-pqpj","publishedAt":"2026-03-16T15:14:55.000Z","cveId":"CVE-2025-69196","cweIds":["CWE-863"],"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":["other"],"issueType":"vulnerability","affectedPackages":["fastmcp@< 2.14.2 (fixed: 2.14.2)"],"affectedPackageNames":["fastmcp"],"affectedPackageRefs":["pypi:fastmcp"],"affectedVendors":[],"affectedVendorsRaw":["FastMCP","MCP","GitHub"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00358,"epssCheckedAt":"2026-10-10T04:57:17.354Z","kevDateAdded":null,"advisoryAliases":["GHSA-5h2m-4q8j-pqpj"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2026-03-16T15:14:55.000Z","capecIds":["CAPEC-122"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}