Executive brief
FastMCP is a framework used to build Model Context Protocol (MCP) applications, which often integrate with external services like GitHub. A security flaw in its authentication proxy allows an attacker to trick a victim into unintentionally granting the attacker access to the victim's account. If exploited, an attacker could gain unauthorized access to a user's private data or resources on connected platforms like GitHub without the user's knowledge.
Technical details
A 'Confused Deputy' vulnerability exists in the FastMCP OAuthProxy component due to insufficient validation of the user's consent state during the Identity Provider (IdP) callback. Specifically, the `OAuthProxy._handle_idp_callback` function does not verify that the browser submitting the authorization code is the same browser that initiated the consent flow. An attacker can initiate an OAuth flow, capture the authorization URL, and lure a victim into clicking it. Because GitHub (and other IdPs) may skip the consent screen for previously authorized applications, the victim's browser automatically completes the callback, providing the attacker's client with a valid authorization code linked to the victim's account. This allows the attacker to exchange the code for an access token and impersonate the victim on the MCP server. The issue is addressed in version 3.2.0 by implementing browser-bound state validation.
Affected products
- jlowin fastmcp < 3.2.0
Timeline
- 2026-03-31: advisory: Vendor advisory published on GitHub
- 2026-04-03: disclosed: CVE published to NVD
- 2026-04-03: patched: Fix released in version 3.2.0