fastmcp is vulnerable to Open Redirect
80
High Risk
Redirect URI allowlisting matched paths with fnmatch semantics where wildcards can span slash boundaries. An attacker could register a redirect URI whose path contains dot-segments such that it matches an operator prefix during validation yet normalizes to a different path when the browser resolves a redirect target. The validator now rejects any path containing . or .. segments in both raw and percent-decoded forms before pattern matching, closing prefix bypasses that relied on RFC 3986 dot-segment removal.
You are affected if you are using a version that falls within the vulnerable range.
fastmcp is vulnerable to Open Redirect in versions 3.0.0 - 3.2.4.
Upgrade the fastmcp library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant