Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-mxxr-jv3v-6pgc | FastMCP vulnerable to reflected XSS in client's callback page |
Fri, 07 Nov 2025 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jlowin
Jlowin fastmcp |
|
| CPEs | cpe:2.3:a:jlowin:fastmcp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Jlowin
Jlowin fastmcp |
|
| Metrics |
cvssV3_1
|
Wed, 29 Oct 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 29 Oct 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fastmcp
Fastmcp fastmcp |
|
| Vendors & Products |
Fastmcp
Fastmcp fastmcp |
Tue, 28 Oct 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0 have a reflected cross-site scripting vulnerability in the OAuth client callback page (oauth_callback.py) where unescaped user-controlled values are inserted into the generated HTML, allowing arbitrary JavaScript execution in the callback server origin. The issue is fixed in version 2.13.0. | |
| Title | FastMCP vulnerable to reflected XSS in client's callback page | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-10-29T15:52:44.433Z
Reserved: 2025-10-22T18:55:48.012Z
Link: CVE-2025-62800
Updated: 2025-10-29T15:52:31.593Z
Status : Analyzed
Published: 2025-10-28T22:15:36.983
Modified: 2025-11-07T01:49:53.133
Link: CVE-2025-62800
No data.
OpenCVE Enrichment
Updated: 2025-10-29T10:57:40Z
Github GHSA