{"data":{"id":"dae31561-6925-4d76-b166-b632ec699afd","title":"GHSA-c2jp-c369-7pvx: FastMCP Auth Integration Allows for Confused Deputy Account Takeover","summary":"FastMCP's Entra ID integration, as documented, makes the MCP server act as both an OAuth client to Entra ID and an authorization server to MCP clients, with its own `/authorize`, `/token` and `/register` endpoints. The reported issue is a confused deputy scenario that can lead to account takeover, though the source text provided is truncated before the attack details are stated.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-c2jp-c369-7pvx","publishedAt":"2025-10-29T15:38:07.000Z","cveId":null,"cweIds":["CWE-287"],"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":["other"],"issueType":"vulnerability","affectedPackages":["fastmcp@< 2.13.0 (fixed: 2.13.0)"],"affectedPackageNames":["fastmcp"],"affectedPackageRefs":["pypi:fastmcp"],"affectedVendors":["Microsoft"],"affectedVendorsRaw":["FastMCP","Entra ID","MCP server"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":["GHSA-c2jp-c369-7pvx"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2025-10-29T15:38:07.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}