fastmcp is vulnerable to Authorization Bypass
71
High Risk
List and call helpers were cached under a single global key while per-tool authorization filtering still ran inside the downstream handler. A caller with broader scopes could populate the cache with tool, resource, or prompt payloads that a later caller with narrower scopes then received without re-running those filters. Cache keys now incorporate a partition derived from the caller access token so authenticated tenants do not reuse one another’s cache entries; unauthenticated callers share one anonymous bucket so single-user setups keep prior behavior.
You are affected if you are using a version that falls within the vulnerable range.
fastmcp is vulnerable to Authorization Bypass in versions 3.0.0 - 3.2.4.
Upgrade the fastmcp library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant