Skip to content
HighVulnerability

GHSA-rww4-4w9c-7733: FastMCP: Missing Consent Verification in OAuth Proxy Callback Facilitates Confused Deputy Vulnerabilities

Published
Record updated
View JSON
Affected
  • fastmcp < 3.2.0
Fixed in
3.2.0
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.3%

Summary

The FastMCP OAuthProxy does not verify user consent when it receives an authorization code from the identity provider, in its _handle_idp_callback function. Because GitHub skips the consent page for previously authorized clients, an attacker can capture a GitHub authorization URL after consenting and lure a logged-in victim to open it. The victim's browser then redirects to the malicious client's callback with a valid authorization code, which the attacker can exchange for an access token to the benign MCP server tied to the victim's GitHub account. The issue was verified only for GitHubProvider, but the flaw affects any OAuth integration whose identity provider skips consent.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.