CVE-2026-27124
CVE-2026-27124 is a medium-severity vulnerability in Jlowin Fastmcp with a CVSS 3.x base score of 6.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-441.
Key facts
- Severity: Medium (CVSS 3.x base score 6.1)
- CVSS v4: 8.2
- EPSS exploit prediction: 0% (21st percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-18758
- Weakness: CWE-441
- Affected product: Jlowin Fastmcp
- Published:
- Last modified:
Description
FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, while testing the GitHubProvider OAuth integration, which allows authentication to a FastMCP MCP server via a FastMCP OAuthProxy using GitHub OAuth, it was discovered that the FastMCP OAuthProxy does not properly validate the user's consent upon receiving the authorization code from GitHub. In combination with GitHub’s behavior of skipping the consent page for previously authorized clients, this introduces a Confused Deputy vulnerability. This issue has been patched in version 3.2.0.
Frequently asked questions
- What is CVE-2026-27124?
- FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, while testing the GitHubProvider OAuth integration, which allows authentication to a FastMCP MCP server via a FastMCP OAuthProxy using GitHub OAuth, it was discovered that the FastMCP OAuthProxy does not properly validate the user's consent upon receiving the authorization code from GitHub. In combination with GitHub’s behavior of skipping the consent page for previously authorized clients, this introduces a Confused Deputy vulnerability. This issue has been patched in version 3.2.0.
- How severe is CVE-2026-27124?
- CVE-2026-27124 has a CVSS 3.x base score of 6.1, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and user interaction. Impact on confidentiality is low, integrity low, and availability none.
- Is CVE-2026-27124 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (21st percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-27124?
- CVE-2026-27124 affects Jlowin Fastmcp. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-27124?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2026-27124 have an EU (EUVD) identifier?
- Yes. CVE-2026-27124 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-18758.
- When was CVE-2026-27124 published?
- CVE-2026-27124 was published on 2026-04-03 and last updated on 2026-07-24.
References
Affected products (1)
- cpe:2.3:a:jlowin:fastmcp:*:*:*:*:*:*:*:*
More vulnerabilities in Jlowin Fastmcp
- CVE-2026-32871 — Critical (CVSS 10.0): FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP…
- CVE-2025-62801 — High (CVSS 7.8): FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0, a command-injection…
- CVE-2025-64340 — Medium (CVSS 6.7): FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, server names containing shell…
- CVE-2025-69196 — Medium (CVSS 6.5): FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly…
- CVE-2025-62800 — Medium (CVSS 6.1): FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0 have a reflected cross-site…
All CVEs affecting Jlowin Fastmcp →
Other CWE-441 vulnerabilities
- CVE-2026-102255 — Critical (CVSS 10.0): A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended…
- CVE-2026-69399 — Critical (CVSS 10.0): Azure Arc Elevation of Privilege Vulnerability
- CVE-2026-83548 — Critical (CVSS 10.0): A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended…
- CVE-2026-42933 — Critical (CVSS 10.0): Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow…
- CVE-2026-39906 — Critical (CVSS 10.0): Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecated .NET Remoting TCP channel…
- CVE-2026-100706 — Critical (CVSS 9.9): kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath, allowing…