CVE-2025-69196
CVE-2025-69196 is a medium-severity vulnerability in Jlowin Fastmcp with a CVSS 3.x base score of 6.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-863.
Key facts
- Severity: Medium (CVSS 3.x base score 6.5)
- CVSS v4: 7.4
- EPSS exploit prediction: 0% (29th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2025-208759
- Weakness: CWE-863
- Affected product: Jlowin Fastmcp
- Published:
- Last modified:
Description
FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly respect the resource parameter submitted by the client in the authorization and token request. Instead of issuing the token explicitly for the MCP server, the token is issued for the base_url passed to the OAuthProxy during initialization. This issue has been patched 2.14.2.
Frequently asked questions
- What is CVE-2025-69196?
- FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly respect the resource parameter submitted by the client in the authorization and token request. Instead of issuing the token explicitly for the MCP server, the token is issued for the base_url passed to the OAuthProxy during initialization. This issue has been patched 2.14.2.
- How severe is CVE-2025-69196?
- CVE-2025-69196 has a CVSS 3.x base score of 6.5, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and user interaction. Impact on confidentiality is high, integrity none, and availability none.
- Is CVE-2025-69196 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (29th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2025-69196?
- CVE-2025-69196 affects Jlowin Fastmcp. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2025-69196?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2025-69196 have an EU (EUVD) identifier?
- Yes. CVE-2025-69196 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2025-208759.
- When was CVE-2025-69196 published?
- CVE-2025-69196 was published on 2026-03-16 and last updated on 2026-07-15.
References
- https://github.com/PrefectHQ/fastmcp/security/advisories/GHSA-5h2m-4q8j-pqpj
- https://access.redhat.com/errata/RHSA-2026:36350
- https://access.redhat.com/security/cve/CVE-2025-69196
- https://bugzilla.redhat.com/show_bug.cgi?id=2448179
- https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69196.json
Affected products (1)
- cpe:2.3:a:jlowin:fastmcp:*:*:*:*:*:*:*:*
More vulnerabilities in Jlowin Fastmcp
- CVE-2026-32871 — Critical (CVSS 10.0): FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP…
- CVE-2025-62801 — High (CVSS 7.8): FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0, a command-injection…
- CVE-2025-64340 — Medium (CVSS 6.7): FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, server names containing shell…
- CVE-2026-27124 — Medium (CVSS 6.1): FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, while testing the…
- CVE-2025-62800 — Medium (CVSS 6.1): FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0 have a reflected cross-site…
All CVEs affecting Jlowin Fastmcp →
Other CWE-863 (Incorrect Authorization) vulnerabilities
- CVE-2026-69555 — Critical (CVSS 10.0): Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-71398 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary…
- CVE-2026-27302 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary…
- CVE-2026-48449 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary…
- CVE-2026-48286 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an Incorrect Authorization…
- CVE-2026-48303 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Authorization…
Browse all CWE-863 (Incorrect Authorization) vulnerabilities →