CVE-2025-64340: FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, server names containing shell m
Summary
FastMCP (a framework for building MCP applications, which are tools that extend AI assistants) has a command injection vulnerability (a security flaw where an attacker can run unauthorized commands) in versions before 3.2.0 on Windows. When server names contain shell metacharacters like '&', they can be misinterpreted by the Windows command interpreter and allow attackers to execute malicious commands during installation.
Solution / Mitigation
Update FastMCP to version 3.2.0 or later, where this issue has been patched.
Vulnerability Details
6.7(medium)
EPSS: 0.0%
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
local
high
low
required
April 3, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-64340
First tracked: April 3, 2026 at 02:07 PM
Classified by LLM (prompt v3) · confidence: 85%