CVE-2025-69196 - CVE House
Back to Database
Status published High CVE-2025-69196

FastMCP OAuth Proxy token reuse across MCP servers

Vulnerability Description

FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly respect the resource parameter submitted by the client in the authorization and token request. Instead of issuing the token explicitly for the MCP server, the token is issued for the base_url passed to the OAuthProxy during initialization. This issue has been patched 2.14.2.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-69196

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

fastmcp
Vulnerable Versions:
< 2.14.2

Timeline

Official Publish: March 16th, 2026
Last Modified: July 15th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)