HighVulnerability
GHSA-c2jp-c369-7pvx: FastMCP Auth Integration Allows for Confused Deputy Account Takeover
- Identifier
- GHSA-c2jp-c369-7pvx
- Published
- Record updated
- Affected
- fastmcp < 2.13.0
- Fixed in
- 2.13.0
Summary
FastMCP's Entra ID integration, as documented, makes the MCP server act as both an OAuth client to Entra ID and an authorization server to MCP clients, with its own `/authorize`, `/token` and `/register` endpoints. The reported issue is a confused deputy scenario that can lead to account takeover, though the source text provided is truncated before the attack details are stated.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- fastmcpPyPILLM dependency since 2024-11-30 · 15 tracked dependents
Topics
Related items
- HighGHSA-h4xc-3qfq-jf93: Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): a website visited by the developer can trigger agent runs and server-side tool execution on the local chat endpointSame vendor · GitHub Advisory Database
- LowGHSA-6gw6-rv2g-25mg: Kiota: Unsafe oauth_card_path references in Kiota-generated API plugin manifestsSame vendor · GitHub Advisory Database
- MediumCVE-2026-89278: GPTranslate WordPress plugin exposes plaintext API key to unauthenticated usersSame vendor · NVD/CVE Database
- HighCVE-2026-85887: M365 Copilot incorrect permission assignment allows information disclosureSame vendor · NVD/CVE Database
- CriticalCVE-2026-85885: M365 Copilot command injection allows privilege elevation over a networkSame vendor · NVD/CVE Database