Skip to content
HighVulnerability

GHSA-c2jp-c369-7pvx: FastMCP Auth Integration Allows for Confused Deputy Account Takeover

Published
Record updated
View JSON
Affected
  • fastmcp < 2.13.0
Fixed in
2.13.0

Summary

FastMCP's Entra ID integration, as documented, makes the MCP server act as both an OAuth client to Entra ID and an authorization server to MCP clients, with its own `/authorize`, `/token` and `/register` endpoints. The reported issue is a confused deputy scenario that can lead to account takeover, though the source text provided is truncated before the attack details are stated.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.