CVE-2026-27124

FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, while testing the GitHubProvider OAuth integration, which allows authentication to a FastMCP MCP server via a FastMCP OAuthProxy using GitHub OAuth, it was discovered that the FastMCP OAuthProxy does not properly validate the user's consent upon receiving the authorization code from GitHub. In combination with GitHub’s behavior of skipping the consent page for previously authorized clients, this introduces a Confused Deputy vulnerability. This issue has been patched in version 3.2.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jlowin:fastmcp:*:*:*:*:*:*:*:*

History

22 Apr 2026, 14:37

Type Values Removed Values Added
References () https://github.com/PrefectHQ/fastmcp/security/advisories/GHSA-rww4-4w9c-7733 - () https://github.com/PrefectHQ/fastmcp/security/advisories/GHSA-rww4-4w9c-7733 - Exploit, Mitigation, Vendor Advisory
CPE cpe:2.3:a:jlowin:fastmcp:*:*:*:*:*:*:*:*
First Time Jlowin
Jlowin fastmcp
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

03 Apr 2026, 17:16

Type Values Removed Values Added
References () https://github.com/PrefectHQ/fastmcp/security/advisories/GHSA-rww4-4w9c-7733 - () https://github.com/PrefectHQ/fastmcp/security/advisories/GHSA-rww4-4w9c-7733 -

03 Apr 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-03 16:16

Updated : 2026-04-22 14:37


NVD link : CVE-2026-27124

Mitre link : CVE-2026-27124

CVE.ORG link : CVE-2026-27124


JSON object : View

Products Affected

jlowin

  • fastmcp
CWE
CWE-441

Unintended Proxy or Intermediary ('Confused Deputy')