{"data":{"ecosystem":"pypi","name":"fastmcp","url":"https://aisecwatch.com/packages/pypi/fastmcp","latestVersion":"4.1.0","firstReleaseAt":"2024-11-30T02:11:15.425Z","repository":"https://github.com/PrefectHQ/fastmcp","llm":{"exposure":"direct","depth":0,"integratedAt":"2024-11-30T02:11:15.425Z","integratedVersion":"0.1.0","sdks":["fastmcp"],"path":[]},"authority":{"profile":[],"fromDependencies":[]},"dependencies":[{"ecosystem":"pypi","name":"fastmcp-slim","versionSpec":"==4.1.0","scope":"runtime"},{"ecosystem":"pypi","name":"fastmcp-tasks","versionSpec":"==4.1.0","scope":"extra:tasks"}],"advisories":[{"id":"3c5c5cda-8260-42bb-a73e-0922c8d5afb9","url":"https://aisecwatch.com/issues/3c5c5cda-8260-42bb-a73e-0922c8d5afb9","cveId":"CVE-2025-64340","title":"CVE-2025-64340: FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, server names containing shell…","headline":"FastMCP command injection through server names in install commands on Windows","severity":"medium","publishedAt":"2026-04-03T16:16:23.010Z","affected":["fastmcp@< 3.2.0 (fixed: 3.2.0)"],"epssScore":0.00735,"matchedBy":"ecosystem"},{"id":"0af4e7a5-4e5f-40fc-9cc0-fd5780f20ead","url":"https://aisecwatch.com/issues/0af4e7a5-4e5f-40fc-9cc0-fd5780f20ead","cveId":"CVE-2026-32871","title":"GHSA-vv7q-7jx5-f767: FastMCP OpenAPI Provider has an SSRF & Path Traversal Vulnerability","headline":null,"severity":"critical","publishedAt":"2026-03-31T22:53:21.000Z","affected":["fastmcp@< 3.2.0 (fixed: 3.2.0)"],"epssScore":0.01369,"matchedBy":"ecosystem"},{"id":"19cd571e-fe36-4d3e-93fb-42f17e4bbb63","url":"https://aisecwatch.com/issues/19cd571e-fe36-4d3e-93fb-42f17e4bbb63","cveId":"CVE-2026-27124","title":"GHSA-rww4-4w9c-7733: FastMCP: Missing Consent Verification in OAuth Proxy Callback Facilitates Confused Deputy Vulnerabilities","headline":null,"severity":"high","publishedAt":"2026-03-31T22:32:28.000Z","affected":["fastmcp@< 3.2.0 (fixed: 3.2.0)"],"epssScore":0.00305,"matchedBy":"ecosystem"},{"id":"9c9a1e47-24fd-45e2-a3a2-36ed67614aa5","url":"https://aisecwatch.com/issues/9c9a1e47-24fd-45e2-a3a2-36ed67614aa5","cveId":"CVE-2025-69196","title":"GHSA-5h2m-4q8j-pqpj: FastMCP OAuth Proxy token reuse across MCP servers","headline":null,"severity":"high","publishedAt":"2026-03-16T15:14:55.000Z","affected":["fastmcp@< 2.14.2 (fixed: 2.14.2)"],"epssScore":0.00358,"matchedBy":"ecosystem"},{"id":"58cee527-90cb-4d38-b158-f482dcb56f9f","url":"https://aisecwatch.com/issues/58cee527-90cb-4d38-b158-f482dcb56f9f","cveId":null,"title":"GHSA-rcfx-77hg-w2wv: FastMCP updated to MCP 1.23+ due to CVE-2025-66416","headline":null,"severity":"high","publishedAt":"2025-12-26T23:20:50.000Z","affected":["fastmcp@< 2.14.0 (fixed: 2.14.0)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"3662891d-5af8-48c6-a89c-3b5a2195c4d4","url":"https://aisecwatch.com/issues/3662891d-5af8-48c6-a89c-3b5a2195c4d4","cveId":"CVE-2025-62801","title":"GHSA-rj5c-58rq-j5g5: FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name","headline":null,"severity":"medium","publishedAt":"2025-10-29T15:39:03.000Z","affected":["fastmcp@< 2.13.0 (fixed: 2.13.0)"],"epssScore":0.00227,"matchedBy":"ecosystem"},{"id":"d7e7cd8a-9128-498a-ab96-4520bdbe3a9d","url":"https://aisecwatch.com/issues/d7e7cd8a-9128-498a-ab96-4520bdbe3a9d","cveId":"CVE-2025-62800","title":"GHSA-mxxr-jv3v-6pgc: FastMCP vulnerable to reflected XSS in client's callback page","headline":null,"severity":"medium","publishedAt":"2025-10-29T15:38:29.000Z","affected":["fastmcp@< 2.13.0 (fixed: 2.13.0)"],"epssScore":0.00276,"matchedBy":"ecosystem"},{"id":"dae31561-6925-4d76-b166-b632ec699afd","url":"https://aisecwatch.com/issues/dae31561-6925-4d76-b166-b632ec699afd","cveId":null,"title":"GHSA-c2jp-c369-7pvx: FastMCP Auth Integration Allows for Confused Deputy Account Takeover","headline":null,"severity":"high","publishedAt":"2025-10-29T15:38:07.000Z","affected":["fastmcp@< 2.13.0 (fixed: 2.13.0)"],"epssScore":null,"matchedBy":"ecosystem"}],"checkedAt":"2026-10-09T21:55:10.545Z"},"meta":{"advisoryMatching":"by package name and ecosystem; an advisory with no ecosystem recorded for the package is matched by name alone"}}