{"data":{"id":"3662891d-5af8-48c6-a89c-3b5a2195c4d4","title":"GHSA-rj5c-58rq-j5g5: FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name","summary":"A command-injection flaw (CWE-78) in FastMCP's Cursor installer lets an attacker who controls the server_name field run arbitrary OS commands on Windows hosts running fastmcp install cursor. The server_name value is embedded unescaped in a cursor:// deeplink, which is opened with shell=True through cmd.exe /c start, so cmd metacharacters such as & or | spawn an attacker-chosen process.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-rj5c-58rq-j5g5","publishedAt":"2025-10-29T15:39:03.000Z","cveId":"CVE-2025-62801","cweIds":["CWE-78"],"cvssScore":null,"cvssSeverity":"medium","severity":"medium","attackType":["other"],"issueType":"vulnerability","affectedPackages":["fastmcp@< 2.13.0 (fixed: 2.13.0)"],"affectedPackageNames":["fastmcp"],"affectedPackageRefs":["pypi:fastmcp"],"affectedVendors":[],"affectedVendorsRaw":["FastMCP","Cursor"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00227,"epssCheckedAt":"2026-10-10T04:57:16.014Z","kevDateAdded":null,"advisoryAliases":["GHSA-rj5c-58rq-j5g5"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2025-10-29T15:39:03.000Z","capecIds":["CAPEC-88"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}