Repository navigation
Conversation
FastMCP interpolates tool arguments into backend URL path templates. A path-parameter value containing separators or dot-segments (raw or percent/backslash-encoded) escaped the intended /api/v1 prefix, letting callers probe undocumented backend routes such as /api/internal/* via the response differential. Add a PathTraversalGuardMiddleware that rejects such values for the parameters interpolated into the request path (derived from the OpenAPI path templates and in:path declarations), before any request is forwarded. Non-path params (e.g. free-text context) are unaffected. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Contributor
Author
|
Superseded by #16, which upgrades to fastmcp 4. That version percent-encodes OpenAPI path parameters, so a path-parameter value can no longer break out of its URL segment and the argument-level guard here is redundant. Closing rather than merging to keep a single mechanism for COR2-475. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
FastMCP interpolates tool arguments directly into the backend URL path template, unescaped. A path-parameter value containing separators or dot-segments escapes the intended
/api/v1prefix, letting a caller reach undocumented backend routes such as/api/internal/*— with the caller's bearer token attached.Reported by Cimpress during a penetration test (COR2-349 umbrella; this is the MCP half).
Verified on the pinned
fastmcp==2.12.3:Two mechanisms combine: fastmcp substitutes path params with a plain
str.replace(no URL-encoding), and httpx then resolves the dot-segments per RFC 3986 when building the request — so the traversal is already resolved client-side, before anything reaches the network.Fix
Add
PathTraversalGuardMiddleware, which rejects path-parameter values containing separators or dot-segments (raw, percent-encoded, or backslash-encoded) before the request is composed. The set of guarded parameters is derived from the spec's own path templates andin: pathdeclarations, so query and body parameters (e.g. free-textcontext) are unaffected.Testing
tests/test_security.py— 23 tests covering the token set, param extraction, and middleware behaviourswagger.json: guard covers 17 path params;../../internal/usersis refused with no request sent, legitimate tags pass throughNotes
CD-321(the original ticket); the work is tracked under COR2-475.create_mcp_server(), so it needs its own wiring — that is cortexapps/cortex-remote-mcp#(companion PR), which is independent of this one and does not need it to land first.🤖 Generated with Claude Code
https://claude.ai/code/session_01LZtC15RMphgMhtsoDh4i4u