PT-2025-44218 · Fastmcp · Fastmcp

Published

2025-10-28

·

Updated

2026-04-14

·

CVE-2025-62801

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FastMCP versions prior to 2.13.0
Description FastMCP, a framework for building MCP applications, contains a command-injection issue. An attacker who can control the server name field of an MCP can execute arbitrary OS commands on Windows hosts running fastmcp install cursor.
Recommendations Update to version 2.13.0 or later.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-62801
GHSA-RJ5C-58RQ-J5G5

Affected Products

Fastmcp