FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0 have a reflected cross-site scripting vulnerability in the OAuth client callback page (oauth_callback.py) where unescaped user-controlled values are inserted into the generated HTML, allowing arbitrary JavaScript execution in the callback server origin. The issue is fixed in version 2.13.0.
History

Wed, 29 Oct 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Oct 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Fastmcp
Fastmcp fastmcp
Vendors & Products Fastmcp
Fastmcp fastmcp

Tue, 28 Oct 2025 21:45:00 +0000

Type Values Removed Values Added
Description FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0 have a reflected cross-site scripting vulnerability in the OAuth client callback page (oauth_callback.py) where unescaped user-controlled values are inserted into the generated HTML, allowing arbitrary JavaScript execution in the callback server origin. The issue is fixed in version 2.13.0.
Title FastMCP vulnerable to reflected XSS in client's callback page
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-10-28T21:34:40.392Z

Updated: 2025-10-29T15:52:44.433Z

Reserved: 2025-10-22T18:55:48.012Z

Link: CVE-2025-62800

cve-icon Vulnrichment

Updated: 2025-10-29T15:52:31.593Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-28T22:15:36.983

Modified: 2025-10-30T15:05:32.197

Link: CVE-2025-62800

cve-icon Redhat

No data.