FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, while testing the GitHubProvider OAuth integration, which allows authentication to a FastMCP MCP server via a FastMCP OAuthProxy using GitHub OAuth, it was discovered that the FastMCP OAuthProxy does not properly validate the user's consent upon receiving the authorization code from GitHub. In combination with GitHub’s behavior of skipping the consent page for previously authorized clients, this introduces a Confused Deputy vulnerability. This issue has been patched in version 3.2.0.
References
| Link | Resource |
|---|---|
| https://github.com/PrefectHQ/fastmcp/security/advisories/GHSA-rww4-4w9c-7733 | Exploit Mitigation Vendor Advisory |
| https://github.com/PrefectHQ/fastmcp/security/advisories/GHSA-rww4-4w9c-7733 | Exploit Mitigation Vendor Advisory |
Configurations
History
22 Apr 2026, 14:37
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/PrefectHQ/fastmcp/security/advisories/GHSA-rww4-4w9c-7733 - Exploit, Mitigation, Vendor Advisory | |
| CPE | cpe:2.3:a:jlowin:fastmcp:*:*:*:*:*:*:*:* | |
| First Time |
Jlowin
Jlowin fastmcp |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
03 Apr 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/PrefectHQ/fastmcp/security/advisories/GHSA-rww4-4w9c-7733 - |
03 Apr 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-03 16:16
Updated : 2026-04-22 14:37
NVD link : CVE-2026-27124
Mitre link : CVE-2026-27124
CVE.ORG link : CVE-2026-27124
JSON object : View
Products Affected
jlowin
- fastmcp
CWE
CWE-441
Unintended Proxy or Intermediary ('Confused Deputy')
