FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly respect the resource parameter submitted by the client in the authorization and token request. Instead of issuing the token explicitly for the MCP server, the token is issued for the base_url passed to the OAuthProxy during initialization. This issue has been patched 2.14.2.
Metrics
Affected Vendors & Products
References
History
Mon, 16 Mar 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Mar 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly respect the resource parameter submitted by the client in the authorization and token request. Instead of issuing the token explicitly for the MCP server, the token is issued for the base_url passed to the OAuthProxy during initialization. This issue has been patched 2.14.2. | |
| Title | FastMCP OAuth Proxy token reuse across MCP servers | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-16T19:09:43.436Z
Reserved: 2025-12-29T14:34:16.261Z
Link: CVE-2025-69196
Updated: 2026-03-16T19:09:36.408Z
Status : Received
Published: 2026-03-16T19:16:14.397
Modified: 2026-03-16T19:16:14.397
Link: CVE-2025-69196
No data.
OpenCVE Enrichment
No data.