Skip to content
HighVulnerability

GHSA-rcfx-77hg-w2wv: FastMCP updated to MCP 1.23+ due to CVE-2025-66416

Published
Record updated
View JSON
Affected
  • fastmcp < 2.14.0
Fixed in
2.14.0

Summary

GHSA-rcfx-77hg-w2wv concerns FastMCP, which does not use the affected components of the MCP SDK directly. However, FastMCP versions prior to 2.14.0 allowed MCP SDK versions below 1.23, which are vulnerable to CVE-2025-66416.

Mitigation

Upgrade to FastMCP 2.14.0 or later.