CVE-2025-62800

FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0 have a reflected cross-site scripting vulnerability in the OAuth client callback page (oauth_callback.py) where unescaped user-controlled values are inserted into the generated HTML, allowing arbitrary JavaScript execution in the callback server origin. The issue is fixed in version 2.13.0.
CVSS

No CVSS.

Configurations

No configuration.

History

29 Oct 2025, 16:15

Type Values Removed Values Added
References () https://github.com/jlowin/fastmcp/security/advisories/GHSA-mxxr-jv3v-6pgc - () https://github.com/jlowin/fastmcp/security/advisories/GHSA-mxxr-jv3v-6pgc -

28 Oct 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-28 22:15

Updated : 2025-10-30 15:05


NVD link : CVE-2025-62800

Mitre link : CVE-2025-62800

CVE.ORG link : CVE-2025-62800


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')