GHSA-5h2m-4q8j-pqpj: FastMCP OAuth Proxy token reuse across MCP servers
- Identifiers
- CVE-2025-69196GHSA-5h2m-4q8j-pqpj
- Published
- Record updated
- Affected
- fastmcp < 2.14.2
- Fixed in
- 2.14.2
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.4%
Summary
The FastMCP OAuth Proxy ignores the client-supplied `resource` parameter in authorization and token requests and issues tokens for the `base_url` set at initialization instead. Because the tokens carry no resource information, a benign MCP server cannot verify that a token was issued for it. An attacker can run a malicious MCP server that advertises the benign proxy as its authorization server, capture the token from a victim's OAuth flow, and replay it against other MCP servers that share that authorization server.
Mitigation
To mitigate this vulnerability, it is recommended to issue tokens specifically for the MCP server submitted in the authorization URL's `resource` GET parameter. In this way, the receiving MCP server will be able to properly verify that the token was indeed issued for it, allowing it to reject tokens stolen by an attack like the one demonstrated above.
Topics
Related items
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpointsSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- CriticalHermes Agent - PKCE Session Takeover via Redirect-URI Parser ConfusionSimilar attack · Tenable Research Advisories
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database