<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T08:09:53.309588+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-fastmcp-cve-2026-32871</id>
    <title>BREW-fastmcp-CVE-2026-32871 — FastMCP OpenAPI Provider has an SSRF &amp; Path Traversal Vulnerability</title>
    <updated>2026-10-03T08:09:53.493295+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: fastmcp</p>
<p>## Technical Description</p>
<p>The `OpenAPIProvider` in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifications. The `RequestDirector` class is responsible for constructing HTTP requests to the backend service.</p>
<p>A critical vulnerability exists in the `_build_url()` method. When an OpenAPI operation defines path parameters (e.g., `/api/v1/users/{user_id}`), the system directly substitutes parameter values into the URL template string **without URL-encoding**. Subsequently, `urllib.parse.urljoin()` resolves the final URL.</p>
<p>Since `urljoin()` interprets `../` sequences as directory traversal, an attacker controlling a path parameter can perform path traversal attacks to escape the intended API prefix and access arbitrary backend endpoints. This results in **authenticated SSRF**, as requests are sent with the authorization headers configured in the MCP provider.</p>
<p>---</p>
<p>## Vulnerable Code</p>
<p>**File:** `fastmcp/utilities/openapi/director.py`</p>
<p>```python
def _build_url(
    self, path_template: str, path_params: dict[str, Any], base_url: str
) -&gt; str:
    # Direct string substitution without encoding
    url_path = path_template
    for param_name, param_value in path_params.items():
        placeholder = f"{{{param_name}}}"
        if placeholder in url_path:
            url_path = url_path.replace(placeholder, str(param_value))</p>
<p># urljoin resolves ../ escape sequences
    return urljoin(base_url.rstrip("/") + "/", url_path.lstrip("/"))
```</p>
<p>### Root Cause</p>
<p>1. Pat…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-fastmcp-cve-2026-32871"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0550</id>
    <title>certfr-2026-avi-0550 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T08:09:53.493429+00:00</updated>
    <content>certfr-2026-avi-0550</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0550"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-337346</id>
    <title>EUVD-2026-337346</title>
    <updated>2026-10-03T08:09:53.493463+00:00</updated>
    <content>EUVD-2026-337346</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-337346"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32871</id>
    <title>fkie_cve-2026-32871</title>
    <updated>2026-10-03T08:09:53.493478+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifications. The RequestDirector class is responsible for constructing HTTP requests to the backend service. A vulnerability exists in the _build_url() method. When an OpenAPI operation defines path parameters (e.g., /api/v1/users/{user_id}), the system directly substitutes parameter values into the URL template string without URL-encoding. Subsequently, urllib.parse.urljoin() resolves the final URL. Since urljoin() interprets ../ sequences as directory traversal, an attacker controlling a path parameter can perform path traversal attacks to escape the intended API prefix and access arbitrary backend endpoints. This results in authenticated SSRF, as requests are sent with the authorization headers configured in the MCP provider. This issue has been patched in version 3.2.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-32871"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vv7q-7jx5-f767</id>
    <title>GHSA-vv7q-7jx5-f767 — FastMCP OpenAPI Provider has an SSRF &amp; Path Traversal Vulnerability</title>
    <updated>2026-10-03T08:09:53.493511+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: fastmcp</p>
<p>## Technical Description</p>
<p>The `OpenAPIProvider` in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifications. The `RequestDirector` class is responsible for constructing HTTP requests to the backend service.</p>
<p>A critical vulnerability exists in the `_build_url()` method. When an OpenAPI operation defines path parameters (e.g., `/api/v1/users/{user_id}`), the system directly substitutes parameter values into the URL template string **without URL-encoding**. Subsequently, `urllib.parse.urljoin()` resolves the final URL.</p>
<p>Since `urljoin()` interprets `../` sequences as directory traversal, an attacker controlling a path parameter can perform path traversal attacks to escape the intended API prefix and access arbitrary backend endpoints. This results in **authenticated SSRF**, as requests are sent with the authorization headers configured in the MCP provider.</p>
<p>---</p>
<p>## Vulnerable Code</p>
<p>**File:** `fastmcp/utilities/openapi/director.py`</p>
<p>```python
def _build_url(
    self, path_template: str, path_params: dict[str, Any], base_url: str
) -&gt; str:
    # Direct string substitution without encoding
    url_path = path_template
    for param_name, param_value in path_params.items():
        placeholder = f"{{{param_name}}}"
        if placeholder in url_path:
            url_path = url_path.replace(placeholder, str(param_value))</p>
<p># urljoin resolves ../ escape sequences
    return urljoin(base_url.rstrip("/") + "/", url_path.lstrip("/"))
```</p>
<p>### Root Cause</p>
<p>1. Pat…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vv7q-7jx5-f767"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-338</id>
    <title>PYSEC-2026-338 — FastMCP OpenAPI Provider has an SSRF &amp; Path Traversal Vulnerability</title>
    <updated>2026-10-03T08:09:53.493604+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: fastmcp</p>
<p>## Technical Description</p>
<p>The `OpenAPIProvider` in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifications. The `RequestDirector` class is responsible for constructing HTTP requests to the backend service.</p>
<p>A critical vulnerability exists in the `_build_url()` method. When an OpenAPI operation defines path parameters (e.g., `/api/v1/users/{user_id}`), the system directly substitutes parameter values into the URL template string **without URL-encoding**. Subsequently, `urllib.parse.urljoin()` resolves the final URL.</p>
<p>Since `urljoin()` interprets `../` sequences as directory traversal, an attacker controlling a path parameter can perform path traversal attacks to escape the intended API prefix and access arbitrary backend endpoints. This results in **authenticated SSRF**, as requests are sent with the authorization headers configured in the MCP provider.</p>
<p>---
 
## Vulnerable Code</p>
<p>**File:** `fastmcp/utilities/openapi/director.py`</p>
<p>```python
 def _build_url(
    self, path_template: str, path_params: dict[str, Any], base_url: str
) -&gt; str:
    # Direct string substitution without encoding
    url_path = path_template
    for param_name, param_value in path_params.items():
        placeholder = f"{{{param_name}}}"
        if placeholder in url_path:
            url_path = url_path.replace(placeholder, str(param_value))</p>
<p># urljoin resolves ../ escape sequences
    return urljoin(base_url.rstrip("/" ) + "/", url_path.lstrip("/"))
```</p>
<p>### Root Cause</p>
<p>1.…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-338"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:36350</id>
    <title>RHSA-2026:36350 — Red Hat Security Advisory: satellite/foreman-mcp-server-rhel9 container image available as a Technology Preview</title>
    <updated>2026-10-03T08:09:53.493696+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>fastmcp: FastMCP: Improper token issuance due to incorrect resource parameter handling python-diskcache: python-diskcache: Arbitrary code execution via insecure pickle deserialization fastmcp: FastMCP: Authenticated Server-Side Request Forgery via path traversal in OpenAPI path parameters urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers urllib3: urllib3: Denial of Service due to excessive HTTP response decompression python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:36350"/>
  </entry>
</feed>
