fastmcp is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
60
Medium Risk
Affected versions of this package unconditionally forward the inbound Authorization header when StreamableHttpTransport or SSETransport connects a session, even for standalone clients used inside server tool handlers. An attacker who invokes a tool that makes outbound requests to another MCP server may cause the credentials to be leaked to that unrelated server, potentially triggering request failures, unintended authentication context reuse, or unauthorized access if the downstream service accepts the leaked token.
You are affected if you are using a version that falls within the vulnerable range.
fastmcp is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 3.0.0 - 3.2.3.
Upgrade the fastmcp library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant