CVE-2026-32871: CWE-918: Server-Side Request Forgery (SSRF) in PrefectHQ fastmcp
FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifications. The RequestDirector class is responsible for constructing HTTP requests to the backend service. A vulnerability exists in the _build_url() method. When an OpenAPI operation defines path parameters (e.g., /api/v1/users/{user_id}), the system directly substitutes parameter values into the URL template string without URL-encoding. Subsequently, urllib.parse.urljoin() resolves the final URL. Since urljoin() interprets ../ sequences as directory traversal, an attacker controlling a path parameter can perform path traversal attacks to escape the intended API prefix and access arbitrary backend endpoints. This results in authenticated SSRF, as requests are sent with the authorization headers configured in the MCP provider. This issue has been patched in version 3.2.0.
AI Analysis
Technical Summary
FastMCP versions before 3.2.0 contain a vulnerability in the OpenAPIProvider's RequestDirector class, specifically in the _build_url() method. When OpenAPI operations define path parameters, these parameters are directly substituted into URL templates without URL-encoding. The use of urllib.parse.urljoin() to resolve the final URL interprets ../ sequences as directory traversal, allowing attackers controlling path parameters to escape the intended API prefix. This results in authenticated SSRF, as requests are sent with the MCP provider's authorization headers. The vulnerability is tracked as CWE-918 and has a CVSS 4.0 score of 10.0 (critical). A fix is available in version 3.2.0.
Potential Impact
An authenticated attacker can exploit this vulnerability to perform SSRF attacks by manipulating path parameters to traverse directories and access arbitrary backend endpoints. The requests are sent with the authorization headers configured in the MCP provider, potentially exposing sensitive internal APIs or data. This can lead to unauthorized access and compromise of backend services.
Mitigation Recommendations
A patch fixing this vulnerability is available in fastmcp version 3.2.0. Users should upgrade to version 3.2.0 or later to remediate the issue. No alternative mitigations or workarounds are indicated in the vendor advisory. Patch status is confirmed by the vendor advisory.
CVE-2026-32871: CWE-918: Server-Side Request Forgery (SSRF) in PrefectHQ fastmcp
Description
FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifications. The RequestDirector class is responsible for constructing HTTP requests to the backend service. A vulnerability exists in the _build_url() method. When an OpenAPI operation defines path parameters (e.g., /api/v1/users/{user_id}), the system directly substitutes parameter values into the URL template string without URL-encoding. Subsequently, urllib.parse.urljoin() resolves the final URL. Since urljoin() interprets ../ sequences as directory traversal, an attacker controlling a path parameter can perform path traversal attacks to escape the intended API prefix and access arbitrary backend endpoints. This results in authenticated SSRF, as requests are sent with the authorization headers configured in the MCP provider. This issue has been patched in version 3.2.0.
CVSS v4.0
Score 10.0critical
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
FastMCP versions before 3.2.0 contain a vulnerability in the OpenAPIProvider's RequestDirector class, specifically in the _build_url() method. When OpenAPI operations define path parameters, these parameters are directly substituted into URL templates without URL-encoding. The use of urllib.parse.urljoin() to resolve the final URL interprets ../ sequences as directory traversal, allowing attackers controlling path parameters to escape the intended API prefix. This results in authenticated SSRF, as requests are sent with the MCP provider's authorization headers. The vulnerability is tracked as CWE-918 and has a CVSS 4.0 score of 10.0 (critical). A fix is available in version 3.2.0.
Potential Impact
An authenticated attacker can exploit this vulnerability to perform SSRF attacks by manipulating path parameters to traverse directories and access arbitrary backend endpoints. The requests are sent with the authorization headers configured in the MCP provider, potentially exposing sensitive internal APIs or data. This can lead to unauthorized access and compromise of backend services.
Mitigation Recommendations
A patch fixing this vulnerability is available in fastmcp version 3.2.0. Users should upgrade to version 3.2.0 or later to remediate the issue. No alternative mitigations or workarounds are indicated in the vendor advisory. Patch status is confirmed by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-03-16T21:03:44.419Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-32871","vendor":"Red Hat"}]
Threat ID: 69ce866ce6bfc5ba1de335fd
Added to database: 04/02/2026, 15:08:28 UTC
Last enriched: 07/16/2026, 08:54:56 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 667
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.