Security: PrefectHQ/fastmcp
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
SSRF & Path Traversal Vulnerability in FastMCP OpenAPI ProviderGHSA-vv7q-7jx5-f767 published
Mar 31, 2026 by jlowinHigh -
Update to MCP 1.23+GHSA-rcfx-77hg-w2wv published
Dec 26, 2025 by jlowinLow -
Missing Consent Verification in OAuth Proxy Callback Facilitates Confused Deputy VulnerabilitiesGHSA-rww4-4w9c-7733 published
Mar 31, 2026 by jlowinHigh -
Improper Resource Handling in FastMCP OAuth Proxy Enables Token Reuse Across MCP ServersGHSA-5h2m-4q8j-pqpj published
Mar 15, 2026 by jlowinModerate -
Command injection via server name in subprocess-backed install commandsGHSA-m8x7-r2rg-vh5g published
Mar 31, 2026 by jlowinModerate -
Reflected XSS in client's callback pageGHSA-mxxr-jv3v-6pgc published
Oct 28, 2025 by jlowinModerate -
FastMCP Auth Integration Allows for Confused Deputy Account TakeoverGHSA-c2jp-c369-7pvx published
Oct 28, 2025 by jlowinHigh -
Windows command injection in FastMCP Cursor installer via server_nameGHSA-rj5c-58rq-j5g5 published
Oct 28, 2025 by jlowinModerate