FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0, a command-injection vulnerability lets any attacker who can influence the server_name field of an MCP execute arbitrary OS commands on Windows hosts that run fastmcp install cursor. This vulnerability is fixed in 2.13.0.
History

Wed, 29 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 29 Oct 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Fastmcp
Fastmcp fastmcp
Vendors & Products Fastmcp
Fastmcp fastmcp

Tue, 28 Oct 2025 21:45:00 +0000

Type Values Removed Values Added
Description FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0, a command-injection vulnerability lets any attacker who can influence the server_name field of an MCP execute arbitrary OS commands on Windows hosts that run fastmcp install cursor. This vulnerability is fixed in 2.13.0.
Title FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 5.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-10-28T21:36:41.167Z

Updated: 2025-10-29T14:54:56.687Z

Reserved: 2025-10-22T18:55:48.012Z

Link: CVE-2025-62801

cve-icon Vulnrichment

Updated: 2025-10-29T14:54:45.554Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-28T22:15:37.950

Modified: 2025-10-30T15:05:32.197

Link: CVE-2025-62801

cve-icon Redhat

No data.