CriticalVulnerability
GHSA-vv7q-7jx5-f767: FastMCP OpenAPI Provider has an SSRF & Path Traversal Vulnerability
- Identifiers
- CVE-2026-32871GHSA-vv7q-7jx5-f767
- Published
- Record updated
- Affected
- fastmcp < 3.2.0
- Fixed in
- 3.2.0
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 1.4%
Summary
GHSA-vv7q-7jx5-f767 affects the OpenAPIProvider in FastMCP, which parses OpenAPI specifications to expose internal APIs to MCP clients. The _build_url() method in fastmcp/utilities/openapi/director.py substitutes path parameter values into URL templates without URL-encoding, and urljoin() then resolves ../ sequences, letting an attacker reach arbitrary backend endpoints. Because requests carry the MCP provider's configured authorization headers, the flaw results in authenticated SSRF.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Topics
Related items
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpointsSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- CriticalHermes Agent - PKCE Session Takeover via Redirect-URI Parser ConfusionSimilar attack · Tenable Research Advisories
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database