HIGH SEVERITYCONFIRMED
fnmatch OAuth redirect URI allows query-param injection and fake-port attacks
Package
fastmcp
Version
2.14.5
Verified
2026-03-28
Description
fastmcp validates OAuth redirect URIs using Python's `fnmatch`. This allows two bypass attacks: (1) query-param injection — `https://evil.com/cb?legit.example.com/anything` matches `https://*.example.com/*`; (2) fake-port — `http://localhost:evil.com` matches `http://localhost:*`. An attacker can receive authorization codes.
Reproduction
import fnmatch
# Attack 1: query-param injection
fnmatch.fnmatch('https://evil.com/cb?legit.example.com/anything', 'https://*.example.com/*') # True
# Attack 2: fake port
fnmatch.fnmatch('http://localhost:evil.com', 'http://localhost:*') # True