CVE-2025-69196: CWE-863: Incorrect Authorization in jlowin fastmcp
FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly respect the resource parameter submitted by the client in the authorization and token request. Instead of issuing the token explicitly for the MCP server, the token is issued for the base_url passed to the OAuthProxy during initialization. This issue has been patched 2.14.2.
AI Analysis
Technical Summary
The vulnerability CVE-2025-69196 in jlowin fastmcp (prior to 2.14.2) is an incorrect authorization issue (CWE-863). The server mishandles the resource parameter in OAuth token requests, issuing tokens for the base_url used during OAuthProxy initialization rather than the intended MCP server resource. This mis-authorization could lead to improper token issuance. The issue has been addressed and fixed in fastmcp version 2.14.2. The CVSS 4.0 score is 7.4 (high severity), indicating a network attack vector with high complexity and user interaction required, and high impact on confidentiality and integrity. Red Hat has published an advisory referencing this CVE and confirms the fix in version 2.14.2.
Potential Impact
Tokens may be issued incorrectly for the base_url instead of the intended MCP server resource, potentially allowing unauthorized access or misuse of tokens. This could compromise the authorization process and affect confidentiality and integrity of the system relying on fastmcp for OAuth token handling.
Mitigation Recommendations
Upgrade fastmcp to version 2.14.2 or later, where this authorization issue has been fixed. No other mitigation is indicated by the vendor advisory. Patch status is confirmed by Red Hat advisory.
CVE-2025-69196: CWE-863: Incorrect Authorization in jlowin fastmcp
Description
FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly respect the resource parameter submitted by the client in the authorization and token request. Instead of issuing the token explicitly for the MCP server, the token is issued for the base_url passed to the OAuthProxy during initialization. This issue has been patched 2.14.2.
CVSS v4.0
Score 7.4high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2025-69196 in jlowin fastmcp (prior to 2.14.2) is an incorrect authorization issue (CWE-863). The server mishandles the resource parameter in OAuth token requests, issuing tokens for the base_url used during OAuthProxy initialization rather than the intended MCP server resource. This mis-authorization could lead to improper token issuance. The issue has been addressed and fixed in fastmcp version 2.14.2. The CVSS 4.0 score is 7.4 (high severity), indicating a network attack vector with high complexity and user interaction required, and high impact on confidentiality and integrity. Red Hat has published an advisory referencing this CVE and confirms the fix in version 2.14.2.
Potential Impact
Tokens may be issued incorrectly for the base_url instead of the intended MCP server resource, potentially allowing unauthorized access or misuse of tokens. This could compromise the authorization process and affect confidentiality and integrity of the system relying on fastmcp for OAuth token handling.
Mitigation Recommendations
Upgrade fastmcp to version 2.14.2 or later, where this authorization issue has been fixed. No other mitigation is indicated by the vendor advisory. Patch status is confirmed by Red Hat advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2025-12-29T14:34:16.261Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2025-69196","vendor":"Red Hat"}]
Threat ID: 69b84f4b771bdb17491f5f9a
Added to database: 03/16/2026, 18:43:23 UTC
Last enriched: 07/16/2026, 08:47:01 UTC
Last updated: 07/31/2026, 19:22:56 UTC
Views: 188
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.