{"data":{"id":"d7e7cd8a-9128-498a-ab96-4520bdbe3a9d","title":"GHSA-mxxr-jv3v-6pgc: FastMCP vulnerable to reflected XSS in client's callback page","summary":"The FastMCP OAuth client's callback page, served by `create_callback_html` in `src/fastmcp/client/oauth_callback.py`, inserts values passed through the `message` parameter without escaping. An attacker can send a crafted `error` GET parameter to the callback server at `localhost:<callback_port>/callback`, causing attacker-controlled JavaScript to run in the callback server's origin. Other parameters reaching the function are also affected, and a malicious authorization server could trigger the same payload by returning the URL in its `authorization_endpoint` field.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-mxxr-jv3v-6pgc","publishedAt":"2025-10-29T15:38:29.000Z","cveId":"CVE-2025-62800","cweIds":["CWE-79"],"cvssScore":null,"cvssSeverity":"medium","severity":"medium","attackType":["other"],"issueType":"vulnerability","affectedPackages":["fastmcp@< 2.13.0 (fixed: 2.13.0)"],"affectedPackageNames":["fastmcp"],"affectedPackageRefs":["pypi:fastmcp"],"affectedVendors":[],"affectedVendorsRaw":["FastMCP","MCP"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00276,"epssCheckedAt":"2026-10-10T04:57:15.709Z","kevDateAdded":null,"advisoryAliases":["GHSA-mxxr-jv3v-6pgc"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2025-10-29T15:38:29.000Z","capecIds":["CAPEC-198","CAPEC-86"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.8,"researchCategory":null,"atlasIds":null}}