HighVulnerability
GHSA-rcfx-77hg-w2wv: FastMCP updated to MCP 1.23+ due to CVE-2025-66416
- Identifier
- GHSA-rcfx-77hg-w2wv
- Published
- Record updated
- Affected
- fastmcp < 2.14.0
- Fixed in
- 2.14.0
Summary
GHSA-rcfx-77hg-w2wv concerns FastMCP, which does not use the affected components of the MCP SDK directly. However, FastMCP versions prior to 2.14.0 allowed MCP SDK versions below 1.23, which are vulnerable to CVE-2025-66416.
Mitigation
Upgrade to FastMCP 2.14.0 or later.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- fastmcpPyPILLM dependency since 2024-11-30 · 15 tracked dependents
Topics
Related items
- HighHermes Agent - Pre-Authentication Disk ConsumptionSimilar attack · Tenable Research Advisories
- MediumHermes Agent - Pre-Authentication Memory ExhaustionSimilar attack · Tenable Research Advisories
- MediumGHSA-v36g-jcw9-x7cw: Pydantic AI: Excessive resource use when local web fetching converts nested HTMLSimilar attack · GitHub Advisory Database
- MediumGHSA-v2xh-2vp8-57h8: Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrlSimilar attack · GitHub Advisory Database
- MediumGHSA-fpf4-vwcp-v4hp: Pydantic AI: Event loop blocked by quadratic title extraction in `web_fetch`Similar attack · GitHub Advisory Database