HIGH SEVERITYCONFIRMED

OAuthProxyProvider(allowed_client_redirect_uris=None) allows ALL redirect URIs

Package
fastmcp
Version
2.14.5
Verified
2026-03-28

Description

In `fastmcp/server/auth/redirect_validation.py:50`, when `allowed_patterns is None` the function returns `True` unconditionally. The documentation states 'If None (default), only localhost redirect URIs are allowed.' The code directly contradicts the documented behavior.

Reproduction

# Source: redirect_validation.py:50
if allowed_patterns is None:
    return True  # 'for DCR compatibility' — but docs say localhost-only
← All bugsScan your code →