PT-2025-44218 · Fastmcp · Fastmcp

CVE-2025-62801

·

Published

2025-10-28

·

Updated

2026-07-07

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FastMCP versions prior to 2.13.0
Description FastMCP, a framework for building MCP applications, contains a command-injection issue. An attacker who can control the server name field of an MCP can execute arbitrary OS commands on Windows hosts running fastmcp install cursor.
Recommendations Update to version 2.13.0 or later.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-62801
GHSA-RJ5C-58RQ-J5G5
PYSEC-2026-1365

Affected Products

Fastmcp