GHSA-rww4-4w9c-7733: FastMCP: Missing Consent Verification in OAuth Proxy Callback Facilitates Confused Deputy Vulnerabilities
- Identifiers
- CVE-2026-27124GHSA-rww4-4w9c-7733
- Published
- Record updated
- Affected
- fastmcp < 3.2.0
- Fixed in
- 3.2.0
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.3%
Summary
The FastMCP OAuthProxy does not verify user consent when it receives an authorization code from the identity provider, in its _handle_idp_callback function. Because GitHub skips the consent page for previously authorized clients, an attacker can capture a GitHub authorization URL after consenting and lure a logged-in victim to open it. The victim's browser then redirects to the malicious client's callback with a valid authorization code, which the attacker can exchange for an access token to the benign MCP server tied to the victim's GitHub account. The issue was verified only for GitHubProvider, but the flaw affects any OAuth integration whose identity provider skips consent.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Topics
Related items
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpointsSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- CriticalHermes Agent - PKCE Session Takeover via Redirect-URI Parser ConfusionSimilar attack · Tenable Research Advisories
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database