GHSA-mxxr-jv3v-6pgc: FastMCP vulnerable to reflected XSS in client's callback page
- Identifiers
- CVE-2025-62800GHSA-mxxr-jv3v-6pgc
- Published
- Record updated
- Affected
- fastmcp < 2.13.0
- Fixed in
- 2.13.0
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.3%
Summary
The FastMCP OAuth client's callback page, served by `create_callback_html` in `src/fastmcp/client/oauth_callback.py`, inserts values passed through the `message` parameter without escaping. An attacker can send a crafted `error` GET parameter to the callback server at `localhost:<callback_port>/callback`, causing attacker-controlled JavaScript to run in the callback server's origin. Other parameters reaching the function are also affected, and a malicious authorization server could trigger the same payload by returning the URL in its `authorization_endpoint` field.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- fastmcpPyPILLM dependency since 2024-11-30 · 15 tracked dependents
Related items
- LowAnthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection FlawsSimilar attack · The Hacker News
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpointsSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- CriticalHermes Agent - PKCE Session Takeover via Redirect-URI Parser ConfusionSimilar attack · Tenable Research Advisories
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading