LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2025-69196

jlowin · fastmcp

Published
CVSS6.5
Severitymedium
WeaknessCWE-863
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Description

FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly respect the resource parameter submitted by the client in the authorization and token request. Instead of issuing the token explicitly for the MCP server, the token is issued for the base_url passed to the OAuthProxy during initialization. This issue has been patched 2.14.2.

References

← Back to the CVE Tracker

Our coverage of CVE-2025-69196

No stories yet. This page updates automatically when we publish reporting that references CVE-2025-69196.