PT-2025-44217 · Fastmcp · Fastmcp

Published

2025-10-28

·

Updated

2026-04-14

·

CVE-2025-62800

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions FastMCP versions prior to 2.13.0
Description FastMCP, a framework for building MCP applications, is affected by a reflected cross-site scripting issue. The problem exists in the OAuth client callback page (oauth callback.py) due to the insertion of unescaped user-controlled values into the generated HTML. This allows for the execution of arbitrary JavaScript code within the callback server origin.
Recommendations Update to version 2.13.0 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-62800
GHSA-MXXR-JV3V-6PGC

Affected Products

Fastmcp