{"id":"CVE-2025-62800","aliases":["GHSA-mxxr-jv3v-6pgc","PYSEC-2026-1364"],"title":"FastMCP vulnerable to reflected XSS in client's callback page","summary":"FastMCP vulnerable to reflected XSS in client's callback page","severity":"medium","vendor":"fastmcp","product":"fastmcp","ecosystem":"pip","affected":["fastmcp < 2.13.0"],"patched":["fastmcp 2.13.0"],"published":"2025-10-29","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-mxxr-jv3v-6pgc","references":[{"url":"https://github.com/jlowin/fastmcp/security/advisories/GHSA-mxxr-jv3v-6pgc"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62800"},{"url":"https://github.com/jlowin/fastmcp/pull/2090"},{"url":"https://github.com/jlowin/fastmcp/commit/2a20f54617a37213ed83894a8c2f0ac38a2e83a3"},{"url":"https://github.com/jlowin/fastmcp"}],"tags":["osv","pip"],"epss":0.00258,"epssPercentile":0.17737,"ingestedAt":"2026-07-08T18:25:51.476Z","slug":"CVE-2025-62800","body":"## Overview\n\n### Summary\nWhile setting up an oauth client, it was noticed that the callback page hosted by the client during the flow embeds user-controlled content without escaping or sanitizing it. This leads to a reflected Cross-Site-Scripting vulnerability.\n\n### Details\nThe affected code is located in *https://github.com/jlowin/fastmcp/blob/main/src/fastmcp/client/oauth_callback.py*, which embeds all values passed to the `create_callback_html` function via the `message` parameter it into the callback page without escaping them. This can, for example, be abused by calling the callback server with an XSS payload inside the `error` GET parameter, the value of which will then be inserted into the callback page, causing the execution of attacker-controlled JavaScript code in the callback server's origin. Note that besides the `error` parameter, other parameters reaching this function are affected too.\n\n### PoC\n1. Setup a simple fastmcp client such as this one (the callback server's port was fixated for simplicity):\n\n```\nurl=\"http://127.0.0.1:8000/mcp\"\noauth = OAuth(mcp_url=url,callback_port=1337)\n\nasync def main():\n    async with Client(url, auth=oauth) as client:\n        await client.ping()\n        \n        # List available operations\n        tools = await client.list_tools()\n\n        print(f\"tools: {tools}\")\n       \nasyncio.run(main())\n```\n\n2. Ensure that the MCP server located at `http://127.0.0.1:8000/mcp` supports oauth.\n3. Start the client.\n4. As soon as the callback server has been started, access `http://localhost:1337/callback?error=<img/src/onerror=alert(window.origin)>`\n\nNote that the exploitation could also for example be initiated by a malicious authorization server by returning the exploitation URL mentioned before in the `authorization_endpoint` field. The client would then automatically open, causing the XSS to trigger immediatly.\n\n### Impact\nThe impact of this XSS vulnerability is the arbitrary JavaScript execution in the victim's browser in the callback server's origin.\n\n## Affected packages\n\n- `fastmcp < 2.13.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `fastmcp 2.13.0`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}