{"data":{"id":"58cee527-90cb-4d38-b158-f482dcb56f9f","title":"GHSA-rcfx-77hg-w2wv: FastMCP updated to MCP 1.23+ due to CVE-2025-66416","summary":"GHSA-rcfx-77hg-w2wv concerns FastMCP, which does not use the affected components of the MCP SDK directly. However, FastMCP versions prior to 2.14.0 allowed MCP SDK versions below 1.23, which are vulnerable to CVE-2025-66416.","solution":"Upgrade to FastMCP 2.14.0 or later.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-rcfx-77hg-w2wv","publishedAt":"2025-12-26T23:20:50.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":["denial_of_service"],"issueType":"vulnerability","affectedPackages":["fastmcp@< 2.14.0 (fixed: 2.14.0)"],"affectedPackageNames":["fastmcp"],"affectedPackageRefs":["pypi:fastmcp"],"affectedVendors":[],"affectedVendorsRaw":["FastMCP","MCP SDK"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":["GHSA-rcfx-77hg-w2wv"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2025-12-26T23:20:50.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["availability"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}