Embedded URLs or IPs: pypi fastmcp
URLs: https://github.com/jlowin/fastmcp, https://picsum.photos/400/300, https://picsum.photos/300/200, https://bsky.social, http://127.0.0.1:8000/mcp, https://your-app.authkit.app, http://127.0.0.1:8000/api/mcp/github/mcp, http://127.0.0.1:8000/api/mcp/google/mcp, https://your-env.scalekit.com, https://mozilla.github.io/pdf.js/web/compressed.tracemonkey-pldi-09.pdf, https://surgemsg.com/, https://api.surgemsg.com/messages, https://api.github.com/repos/, https://valkey.io/, https://gofastmcp.com/docs/tasks, https://gofastmcp.com/clients/auth/oauth#token-storage, https://fastmcp-test-server.example.com, https://dev.example.com, https://gofastmcp.com/deployment/http#mounting-authenticated-servers, http://example.com/api, http://oauth.net/core/2.1/#registration, https://modelcontextprotocol.io/specification/2025-06-18/basic/security_best_practices#confused-deputy-problem, https://gofastmcp.com/servers/auth/oauth-proxy#confused-deputy-attacks, https://openid.net/specs/openid-connect-discovery-1_0.html, https://datatracker.ietf.org/doc/html/rfc8414, https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata, https://datatracker.ietf.org/doc/html/rfc8414#section-2, https://oidc.config.url, https://your.server.url, https://auth0.config.url, https://my-server.com, https://graph.microsoft.com/User.Read, https://app.descope.com/mcp-servers, https://docs.descope.com/identity-federation/inbound-apps/creating-inbound-apps#method-2-dynamic-client-registration-dcr, https://your-fastmcp-server.com, https://api.descope.com, https://discord.com/api/oauth2/@me, https://discord.com/oauth2/authorize, https://discord.com/api/oauth2/token, https://api.github.com/user, https://api.github.com/user/repos, https://github.com/login/oauth/authorize, https://github.com/login/oauth/access_token, https://www.googleapis.com/auth/userinfo.email, https://www.googleapis.com/oauth2/v1/tokeninfo, https://www.googleapis.com/oauth2/v2/userinfo, https://accounts.google.com/o/oauth2/v2/auth, https://oauth2.googleapis.com/token, http://fastmcp.example.com, https://auth.example.com/oauth/introspect, https://fastmcp.example.com, https://app.scalekit.com/, https://docs.scalekit.com/mcp/overview/, https://abc123.supabase.co, https://your-fastmcp-server.com/oauth2/callback, https://workos.com/docs/authkit/mcp/integrating/token-verification, https://your-workos-domain.authkit.app, http://127.0.0.1, https://app.example.com/auth/, https://gofastmcp.com/deployment/asgi, https://github.com/jlowin/fastmcp/issues, https://gofastmcp.com/patterns/decorating-methods, https://gofastmcp.com/docs/servers/tools, https://gofastmcp.com, https://fastmcp.cloud, https://astral.sh/uv/install.sh, https://gofastmcp.com/public/schemas/fastmcp.json/v1.json, https://gofastmcp.com/assets/brand/blue-logo.png, https://api.example.com/v1, http://malicious.com, https://example.com, http://example.com, http://127.0.0.1:3000/path, https://api.example.com/mcp, ftp://example.com, https://mcp.example.com/server1/v1.0/mcp, https://mcp.example.com, https://mcp.example.com/api/mcp/, https://mcp.example.com/api/mcp, https://github.com/jlowin/fastmcp/pull/643, http://example.com/api/sse/stream, http://example.com/api/sse, http://example.com/api/sse/, http://example.com/api/sse?param=value, http://example.com/asset/image.jpg, https://example.com/assets/file, https://example.com:8080/mcp, https://x.com, https://github.com/modelcontextprotocol/python-sdk/pull/659, https://some.fake.url/, https://github.com/settings/developers, http://127.0.0.1:9100/auth/callback, https://api.githubcopilot.com/mcp/, http://example.com/data, https://example.com/.well-known/openid-configuration, https://example.com:8000/, https://example.com/authorize, https://example.com/oauth/token, https://example.com/.well-known/jwks.json, https://cognito-idp.us-east-1.amazonaws.com/us-east-1_XXXXXXXXX, https://test.auth.us-east-1.amazoncognito.com/oauth2/authorize, https://test.auth.us-east-1.amazoncognito.com/oauth2/token, https://cognito-idp.us-east-1.amazonaws.com/us-east-1_XXXXXXXXX/.well-known/jwks.json, https://test.auth.us-east-1.amazoncognito.com/oauth2/userInfo, https://example.com/, https://env-example.com, https://env-example.com/, https://myserver.com, https://myserver.com/, https://envserver.com, https://envserver.com/, https://login.microsoftonline.com/my-tenant-id/oauth2/v2.0/authorize, https://login.microsoftonline.com/my-tenant-id/oauth2/v2.0/token, https://login.microsoftonline.com/my-tenant/discovery/v2.0/keys, https://login.microsoftonline.com/my-tenant/v2.0, https://srv.example, https://should.be.ignored, https://login.microsoftonline.com/test-tenant/oauth2/v2.0/authorize, https://login.microsoftonline.com/test-tenant/oauth2/v2.0/token, https://login.microsoftonline.com/test-tenant/v2.0, https://login.microsoftonline.com/test-tenant/discovery/v2.0/keys, https://login.microsoftonline.us/gov-tenant-id/oauth2/v2.0/authorize, https://login.microsoftonline.us/gov-tenant-id/oauth2/v2.0/token, https://login.microsoftonline.us/gov-tenant-id/v2.0, https://login.microsoftonline.us/gov-tenant-id/discovery/v2.0/keys, https://login.microsoftonline.us/env-tenant-id/oauth2/v2.0/authorize, https://login.microsoftonline.us/env-tenant-id/oauth2/v2.0/token, https://login.microsoftonline.us/env-tenant-id/v2.0, https://login.microsoftonline.us/env-tenant-id/discovery/v2.0/keys, https://graph.microsoft.com/.default, https://graph.microsoft.com/Mail.Send, https://api.descope.com/v1/apps/agentic/P2abc123/M123/.well-known/openid-configuration, https://api.descope.com/v1/apps/agentic/P2env123/M123/.well-known/openid-configuration, https://api.descope.com/v1/apps/P2oldenv123, http://env-server.com, http://env-server.com/, https://api.descope.com/v1/apps/agentic/P2abc123/M123, https://api.descope.com/v1/apps/P2abc123, https://api.descope.com/P2abc123/.well-known/jwks.json, https://api.descope.com/v1/apps/agentic/P2new123/M123/.well-known/openid-configuration, https://old.descope.com, https://api.descope.com/v1/apps/agentic/P2new123/M123, https://api.descope.com/v1/apps/agentic/P2test123/M123/.well-known/openid-configuration, https://github.com/testuser.png, https://www.googleapis.com/auth/userinfo.profile, https://auth.example.com/introspect, https://my-env.scalekit.com, https://legacy.scalekit.com, https://legacy-app.com/, https://preferred-base.com/, https://unused-base.com/, https://env-scalekit.com, https://envserver.com/mcp, https://legacy-env.com/, https://test-env.scalekit.com, http://test-server.com, http://test-server.com/, https://my-env.scalekit.com/, https://my-env.scalekit.com/keys, https://my-env.scalekit.com/resources/sk_resource_456, https://test-env.scalekit.com/token, https://test-env.scalekit.com/authorize, https://test-env.scalekit.com/.well-known/oauth-authorization-server/resources/sk_resource_test_456, https://env123.supabase.co, https://abc123.supabase.co/, https://abc123.supabase.co/auth/v1/.well-known/jwks.json, https://abc123.supabase.co/auth/v1, https://test123.supabase.co, https://test.authkit.app, https://env.authkit.app, https://test.authkit.app/oauth2/authorize, https://test.authkit.app/oauth2/token, https://respectful-lullaby-34-staging.authkit.app, https://auth.example.com, https://my-server.com/.well-known/oauth-protected-resource/api/v1/mcp, https://my-server.com/mcp, https://my-server.com/api/v2/services/mcp, https://test.com, https://myserver.com/register, https://example.com/icon.png, https://test-server.com, https://test-server.com/mcp, https://other-server.com, https://other-server.com/mcp, https://test.example.com, https://api.example.com, https://evil.example.com, https://wrong-api.example.com, https://test.example.com/.well-known/jwks.json, https://any.example.com, https://any-api.example.com, https://other-api.example.com, https://third-party.example.com, https://other-issuer.example.com, https://wrong-issuer.example.com, https://my-auth-server.com, https://myserver.example, https://oauth.example.com/authorize, https://oauth.example.com/token, https://proxy.example.com, https://example.com/custom-icon.png, https://auth.example.com/, https://api.example.com/api, https://api.example.com/api/mcp, https://api.example.com/outer/inner, https://api.example.com/outer/inner/mcp, https://upstream.example.com/authorize, https://upstream.example.com/token, https://api.example.com/api/authorize, https://api.example.com/api/token, https://api.example.com/api/register, https://api.example.com/api/, https://auth.example.com/authorize, https://auth.example.com/token, https://api.example.com/, https://auth.example.com/revoke, https://issuer.example.com, https://docs.example.com, https://auth.com/authorize, https://auth.com/token, https://api.com, https://resource.example.com, https://idp.example.com/authorize, https://idp.example.com/token, https://idp.example.com/.well-known/jwks.json, https://idp.example.com, http://127.0.0.1:3000, https://claude.ai/api/mcp/auth_callback, https://app.example.com/, https://app.example.com/callback, https://anywhere.com:9999/path, https://accounts.google.com/.well-known/openid-configuration, https://example.com/oauth/introspect, http://example.com:3000/callback, https://api.example.com/callback, https://example.com/callback, http://app.example.com/callback, https://app.example.com:8080/auth/callback, https://api.example.com:3000/auth/redirect, http://app.example.com:8080/auth/callback, http://127.0.0.1:8080, https://app.example.com, https://api.trusted.io/auth, https://other.example.com/callback, http://example.com/callback, https://api.example.com/.well-known/oauth-protected-resource/mcp, https://api.example.com/v1/, https://api.example.com/v1/.well-known/oauth-protected-resource/mcp, https://api.example.com/v1/mcp, https://auth1.example.com, https://auth2.example.com, https://auth1.example.com/, https://auth2.example.com/, https://accounts.google.com, https://accounts.google.com/, https://doc.my-server.com/resource-docs, http://test.com, https://resource.example.com/, https://github.com/jlowin/fastmcp/issues/1300, https://raw.githubusercontent.com/github/rest-api-description/refs/heads/main/descriptions-next/ghes-3.17/ghes-3.17.json, https://example.com/greet-icon.png, https://example.com/wave-icon.png, https://example.com/user-icon.png, https://example.com/welcome-icon.png, http://example.com/mcp/, https://mcptest.com, https://client.example.com/callback, https://auth.example.com/register, https://docs.example.com/, https://client.example.com/other-callback, https://client.example.com, https://attacker.example.com/callback, https://api.example.com/v1/users, https://example.com/tool-icon.png, https://example.com/resource-icon.png, https://example.com/template-icon.png, https://example.com/prompt-icon.png, https://example.com/icon-48.png, https://example.com/icon-96.png, https://example.com/icon.svg, http://127.0.0.1:9999/sse/, https://github.com/jlowin/fastmcp/issues/2583, http://example.com/path, https://github.com/jlowin/fastmcp/issues/1369, https://api.example.com/users/123, https://api.example.com/v1/users/123, https://api.example.com/users/42, https://api.example.com/search, https://example.com/calculator.png, https://example.com/data.png, https://example.com/user.png, https://example.com/analyze.png, https://example.com/tool-small.png, https://example.com/tool-large.png, https://example.com/v1-tool.png, https://example.com/server.png, https://example.com/tool.png
Location: Package overview
From: server/hello/requirements.txt → pypi/[email protected]
ℹ Read more on: This package | This alert | What are URL strings?
Next steps: Take a moment to review the security alert
above. Review the linked package source code to understand the potential
risk. Ensure the package is not malicious before proceeding. If you're
unsure how to proceed, reach out to your security team or ask the Socket
team for help at [email protected].
Suggestion: Review all remote URLs to ensure they are intentional, pointing to trusted sources, and not being used for data exfiltration or loading untrusted code at runtime.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore pypi/[email protected]. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.