<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:10:52 +0000</lastBuildDate>
    <item>
      <title>BREW-fastmcp-CVE-2026-32871 — FastMCP OpenAPI Provider has an SSRF &amp; Path Traversal Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/brew-fastmcp-cve-2026-32871</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: fastmcp&lt;/p&gt;
&lt;p&gt;## Technical Description&lt;/p&gt;
&lt;p&gt;The `OpenAPIProvider` in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifications. The `RequestDirector` class is responsible for constructing HTTP requests to the backend service.&lt;/p&gt;
&lt;p&gt;A critical vulnerability exists in the `_build_url()` method. When an OpenAPI operation defines path parameters (e.g., `/api/v1/users/{user_id}`), the system directly substitutes parameter values into the URL template string **without URL-encoding**. Subsequently, `urllib.parse.urljoin()` resolves the final URL.&lt;/p&gt;
&lt;p&gt;Since `urljoin()` interprets `../` sequences as directory traversal, an attacker controlling a path parameter can perform path traversal attacks to escape the intended API prefix and access arbitrary backend endpoints. This results in **authenticated SSRF**, as requests are sent with the authorization headers configured in the MCP provider.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Vulnerable Code&lt;/p&gt;
&lt;p&gt;**File:** `fastmcp/utilities/openapi/director.py`&lt;/p&gt;
&lt;p&gt;```python
def _build_url(
    self, path_template: str, path_params: dict[str, Any], base_url: str
) -&amp;gt; str:
    # Direct string substitution without encoding
    url_path = path_template
    for param_name, param_value in path_params.items():
        placeholder = f&amp;#34;{{{param_name}}}&amp;#34;
        if placeholder in url_path:
            url_path = url_path.replace(placeholder, str(param_value))&lt;/p&gt;
&lt;p&gt;# urljoin resolves ../ escape sequences
    return urljoin(base_url.rstrip(&amp;#34;/&amp;#34;) + &amp;#34;/&amp;#34;, url_path.lstrip(&amp;#34;/&amp;#34;))
```&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;1. Pat…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: fastmcp&lt;/p&gt;
&lt;p&gt;## Technical Description&lt;/p&gt;
&lt;p&gt;The `OpenAPIProvider` in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifications. The `RequestDirector` class is responsible for constructing HTTP requests to the backend service.&lt;/p&gt;
&lt;p&gt;A critical vulnerability exists in the `_build_url()` method. When an OpenAPI operation defines path parameters (e.g., `/api/v1/users/{user_id}`), the system directly substitutes parameter values into the URL template string **without URL-encoding**. Subsequently, `urllib.parse.urljoin()` resolves the final URL.&lt;/p&gt;
&lt;p&gt;Since `urljoin()` interprets `../` sequences as directory traversal, an attacker controlling a path parameter can perform path traversal attacks to escape the intended API prefix and access arbitrary backend endpoints. This results in **authenticated SSRF**, as requests are sent with the authorization headers configured in the MCP provider.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Vulnerable Code&lt;/p&gt;
&lt;p&gt;**File:** `fastmcp/utilities/openapi/director.py`&lt;/p&gt;
&lt;p&gt;```python
def _build_url(
    self, path_template: str, path_params: dict[str, Any], base_url: str
) -&amp;gt; str:
    # Direct string substitution without encoding
    url_path = path_template
    for param_name, param_value in path_params.items():
        placeholder = f&amp;#34;{{{param_name}}}&amp;#34;
        if placeholder in url_path:
            url_path = url_path.replace(placeholder, str(param_value))&lt;/p&gt;
&lt;p&gt;# urljoin resolves ../ escape sequences
    return urljoin(base_url.rstrip(&amp;#34;/&amp;#34;) + &amp;#34;/&amp;#34;, url_path.lstrip(&amp;#34;/&amp;#34;))
```&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;1. Pat…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-fastmcp-cve-2026-32871</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0550 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0550</link>
      <description>certfr-2026-avi-0550</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0550</guid>
    </item>
    <item>
      <title>EUVD-2026-337346</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-337346</link>
      <description>EUVD-2026-337346</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-337346</guid>
    </item>
    <item>
      <title>fkie_cve-2026-32871</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32871</link>
      <description>&lt;p&gt;FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifications. The RequestDirector class is responsible for constructing HTTP requests to the backend service. A vulnerability exists in the _build_url() method. When an OpenAPI operation defines path parameters (e.g., /api/v1/users/{user_id}), the system directly substitutes parameter values into the URL template string without URL-encoding. Subsequently, urllib.parse.urljoin() resolves the final URL. Since urljoin() interprets ../ sequences as directory traversal, an attacker controlling a path parameter can perform path traversal attacks to escape the intended API prefix and access arbitrary backend endpoints. This results in authenticated SSRF, as requests are sent with the authorization headers configured in the MCP provider. This issue has been patched in version 3.2.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifications. The RequestDirector class is responsible for constructing HTTP requests to the backend service. A vulnerability exists in the _build_url() method. When an OpenAPI operation defines path parameters (e.g., /api/v1/users/{user_id}), the system directly substitutes parameter values into the URL template string without URL-encoding. Subsequently, urllib.parse.urljoin() resolves the final URL. Since urljoin() interprets ../ sequences as directory traversal, an attacker controlling a path parameter can perform path traversal attacks to escape the intended API prefix and access arbitrary backend endpoints. This results in authenticated SSRF, as requests are sent with the authorization headers configured in the MCP provider. This issue has been patched in version 3.2.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-32871</guid>
    </item>
    <item>
      <title>GHSA-vv7q-7jx5-f767 — FastMCP OpenAPI Provider has an SSRF &amp; Path Traversal Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vv7q-7jx5-f767</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: fastmcp&lt;/p&gt;
&lt;p&gt;## Technical Description&lt;/p&gt;
&lt;p&gt;The `OpenAPIProvider` in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifications. The `RequestDirector` class is responsible for constructing HTTP requests to the backend service.&lt;/p&gt;
&lt;p&gt;A critical vulnerability exists in the `_build_url()` method. When an OpenAPI operation defines path parameters (e.g., `/api/v1/users/{user_id}`), the system directly substitutes parameter values into the URL template string **without URL-encoding**. Subsequently, `urllib.parse.urljoin()` resolves the final URL.&lt;/p&gt;
&lt;p&gt;Since `urljoin()` interprets `../` sequences as directory traversal, an attacker controlling a path parameter can perform path traversal attacks to escape the intended API prefix and access arbitrary backend endpoints. This results in **authenticated SSRF**, as requests are sent with the authorization headers configured in the MCP provider.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Vulnerable Code&lt;/p&gt;
&lt;p&gt;**File:** `fastmcp/utilities/openapi/director.py`&lt;/p&gt;
&lt;p&gt;```python
def _build_url(
    self, path_template: str, path_params: dict[str, Any], base_url: str
) -&amp;gt; str:
    # Direct string substitution without encoding
    url_path = path_template
    for param_name, param_value in path_params.items():
        placeholder = f&amp;#34;{{{param_name}}}&amp;#34;
        if placeholder in url_path:
            url_path = url_path.replace(placeholder, str(param_value))&lt;/p&gt;
&lt;p&gt;# urljoin resolves ../ escape sequences
    return urljoin(base_url.rstrip(&amp;#34;/&amp;#34;) + &amp;#34;/&amp;#34;, url_path.lstrip(&amp;#34;/&amp;#34;))
```&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;1. Pat…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: fastmcp&lt;/p&gt;
&lt;p&gt;## Technical Description&lt;/p&gt;
&lt;p&gt;The `OpenAPIProvider` in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifications. The `RequestDirector` class is responsible for constructing HTTP requests to the backend service.&lt;/p&gt;
&lt;p&gt;A critical vulnerability exists in the `_build_url()` method. When an OpenAPI operation defines path parameters (e.g., `/api/v1/users/{user_id}`), the system directly substitutes parameter values into the URL template string **without URL-encoding**. Subsequently, `urllib.parse.urljoin()` resolves the final URL.&lt;/p&gt;
&lt;p&gt;Since `urljoin()` interprets `../` sequences as directory traversal, an attacker controlling a path parameter can perform path traversal attacks to escape the intended API prefix and access arbitrary backend endpoints. This results in **authenticated SSRF**, as requests are sent with the authorization headers configured in the MCP provider.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Vulnerable Code&lt;/p&gt;
&lt;p&gt;**File:** `fastmcp/utilities/openapi/director.py`&lt;/p&gt;
&lt;p&gt;```python
def _build_url(
    self, path_template: str, path_params: dict[str, Any], base_url: str
) -&amp;gt; str:
    # Direct string substitution without encoding
    url_path = path_template
    for param_name, param_value in path_params.items():
        placeholder = f&amp;#34;{{{param_name}}}&amp;#34;
        if placeholder in url_path:
            url_path = url_path.replace(placeholder, str(param_value))&lt;/p&gt;
&lt;p&gt;# urljoin resolves ../ escape sequences
    return urljoin(base_url.rstrip(&amp;#34;/&amp;#34;) + &amp;#34;/&amp;#34;, url_path.lstrip(&amp;#34;/&amp;#34;))
```&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;1. Pat…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vv7q-7jx5-f767</guid>
    </item>
    <item>
      <title>PYSEC-2026-338 — FastMCP OpenAPI Provider has an SSRF &amp; Path Traversal Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-338</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: fastmcp&lt;/p&gt;
&lt;p&gt;## Technical Description&lt;/p&gt;
&lt;p&gt;The `OpenAPIProvider` in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifications. The `RequestDirector` class is responsible for constructing HTTP requests to the backend service.&lt;/p&gt;
&lt;p&gt;A critical vulnerability exists in the `_build_url()` method. When an OpenAPI operation defines path parameters (e.g., `/api/v1/users/{user_id}`), the system directly substitutes parameter values into the URL template string **without URL-encoding**. Subsequently, `urllib.parse.urljoin()` resolves the final URL.&lt;/p&gt;
&lt;p&gt;Since `urljoin()` interprets `../` sequences as directory traversal, an attacker controlling a path parameter can perform path traversal attacks to escape the intended API prefix and access arbitrary backend endpoints. This results in **authenticated SSRF**, as requests are sent with the authorization headers configured in the MCP provider.&lt;/p&gt;
&lt;p&gt;---
 
## Vulnerable Code&lt;/p&gt;
&lt;p&gt;**File:** `fastmcp/utilities/openapi/director.py`&lt;/p&gt;
&lt;p&gt;```python
 def _build_url(
    self, path_template: str, path_params: dict[str, Any], base_url: str
) -&amp;gt; str:
    # Direct string substitution without encoding
    url_path = path_template
    for param_name, param_value in path_params.items():
        placeholder = f&amp;#34;{{{param_name}}}&amp;#34;
        if placeholder in url_path:
            url_path = url_path.replace(placeholder, str(param_value))&lt;/p&gt;
&lt;p&gt;# urljoin resolves ../ escape sequences
    return urljoin(base_url.rstrip(&amp;#34;/&amp;#34; ) + &amp;#34;/&amp;#34;, url_path.lstrip(&amp;#34;/&amp;#34;))
```&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;1.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: fastmcp&lt;/p&gt;
&lt;p&gt;## Technical Description&lt;/p&gt;
&lt;p&gt;The `OpenAPIProvider` in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifications. The `RequestDirector` class is responsible for constructing HTTP requests to the backend service.&lt;/p&gt;
&lt;p&gt;A critical vulnerability exists in the `_build_url()` method. When an OpenAPI operation defines path parameters (e.g., `/api/v1/users/{user_id}`), the system directly substitutes parameter values into the URL template string **without URL-encoding**. Subsequently, `urllib.parse.urljoin()` resolves the final URL.&lt;/p&gt;
&lt;p&gt;Since `urljoin()` interprets `../` sequences as directory traversal, an attacker controlling a path parameter can perform path traversal attacks to escape the intended API prefix and access arbitrary backend endpoints. This results in **authenticated SSRF**, as requests are sent with the authorization headers configured in the MCP provider.&lt;/p&gt;
&lt;p&gt;---
 
## Vulnerable Code&lt;/p&gt;
&lt;p&gt;**File:** `fastmcp/utilities/openapi/director.py`&lt;/p&gt;
&lt;p&gt;```python
 def _build_url(
    self, path_template: str, path_params: dict[str, Any], base_url: str
) -&amp;gt; str:
    # Direct string substitution without encoding
    url_path = path_template
    for param_name, param_value in path_params.items():
        placeholder = f&amp;#34;{{{param_name}}}&amp;#34;
        if placeholder in url_path:
            url_path = url_path.replace(placeholder, str(param_value))&lt;/p&gt;
&lt;p&gt;# urljoin resolves ../ escape sequences
    return urljoin(base_url.rstrip(&amp;#34;/&amp;#34; ) + &amp;#34;/&amp;#34;, url_path.lstrip(&amp;#34;/&amp;#34;))
```&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;1.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-338</guid>
    </item>
    <item>
      <title>RHSA-2026:36350 — Red Hat Security Advisory: satellite/foreman-mcp-server-rhel9 container image available as a Technology Preview</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:36350</link>
      <description>&lt;p&gt;fastmcp: FastMCP: Improper token issuance due to incorrect resource parameter handling python-diskcache: python-diskcache: Arbitrary code execution via insecure pickle deserialization fastmcp: FastMCP: Authenticated Server-Side Request Forgery via path traversal in OpenAPI path parameters urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers urllib3: urllib3: Denial of Service due to excessive HTTP response decompression python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;fastmcp: FastMCP: Improper token issuance due to incorrect resource parameter handling python-diskcache: python-diskcache: Arbitrary code execution via insecure pickle deserialization fastmcp: FastMCP: Authenticated Server-Side Request Forgery via path traversal in OpenAPI path parameters urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers urllib3: urllib3: Denial of Service due to excessive HTTP response decompression python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:36350</guid>
    </item>
  </channel>
</rss>
