Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

FastMCP OAuth token audience flaw (CVE-2025-69196) fixed in 2.14.2

FastMCP versions prior to 2.14.2 did not respect the resource parameter submitted by clients in authorization and token requests, issuing tokens for the base_url given to the OAuthProxy rather than explicitly for the MCP server. The issue was patched in version 2.14.2.

Disclosed 16 March 2026 · Record updated 13 September 2026

Impact

OAuth tokens were issued with an incorrect audience (the configured base_url instead of the specific MCP server), weakening token binding for MCP applications built on FastMCP.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2025-69196