Skip to content
MediumVulnerability

GHSA-mxxr-jv3v-6pgc: FastMCP vulnerable to reflected XSS in client's callback page

Published
Record updated
View JSON
Affected
  • fastmcp < 2.13.0
Fixed in
2.13.0
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.3%

Summary

The FastMCP OAuth client's callback page, served by `create_callback_html` in `src/fastmcp/client/oauth_callback.py`, inserts values passed through the `message` parameter without escaping. An attacker can send a crafted `error` GET parameter to the callback server at `localhost:<callback_port>/callback`, causing attacker-controlled JavaScript to run in the callback server's origin. Other parameters reaching the function are also affected, and a malicious authorization server could trigger the same payload by returning the URL in its `authorization_endpoint` field.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.