Skip to content

Conversation

@withsmilo
Copy link

Description

Hi team.
I found fastmcp (under 2.13.0) has a critical security issue below. Please upgrade fastmcp version to address it.

Unintended Proxy or Intermediary ('Confused Deputy') : https://security.snyk.io/vuln/SNYK-PYTHON-FASTMCP-13776148

Fixes: #736

Changes

  • Changed the upper limit of the fastmcp version from 2.4.0 to 2.14.0

Testing

  • Unit tests added/updated
  • Integration tests passed
  • Manual checks performed: [briefly describe]

Checklist

  • Code follows project style guidelines (linting passes).
  • Tests added/updated for changes.
  • All tests pass locally.
  • Documentation updated (if needed).

@withsmilo
Copy link
Author

Hello, @sooperset . Could you please review this pull request? This is related with urgent security issue.

@talg-gloat
Copy link

@sooperset hey, I cant use the library as this security has high vulnerability.
can you go over this PR and if its good, release a newer version? thanks.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Feature]: Upgrade fastmcp dependency to support latest versions in mcp-atlassian

2 participants