CVE-2026-32871 identifies a critical authenticated Server-Side Request Forgery (SSRF) and path traversal vulnerability in FastMCP versions prior to 3.2.0. The flaw occurs because the OpenAPIProvider's RequestDirector fails to URL-encode path parameters, allowing attackers to use directory traversal sequences (e.g., "../") to escape the intended API prefix. With a CVSS score of 10.0, this network-exploitable vulnerability enables an attacker to access arbitrary backend endpoints and send requests using the FastMCP provider's configured authorization headers, leading to severe impact on confidentiality, integrity, and availability. There is currently no public exploit code, active exploitation, or significant community discussion reported. Organizations using FastMCP should upgrade to version 3.2.0 immediately to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.2.0CPE matchmatch criteria | cpe:2.3:a:jlowin:fastmcp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.