CVE 5.4 MEDIUM

FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name_CVE-2025-62801

5.4 / 10
MEDIUM
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0, a command-injection vulnerability lets any attacker who can influence the server_name field of an MCP execute arbitrary OS commands on Windows hosts that run fastmcp install cursor. This vulnerability is fixed in 2.13.0.

Basic Information

ID CVE-2025-62801
Source GitHub_M
Published Oct 28, 2025 at 21:36

Affected Product

Vendor jlowin
Product fastmcp
Version < 2.13.0
Affected Versions jlowin fastmcp < 2.13.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.