fastmcp vulnerabilities
CVEs whose affected-version data names the fastmcp package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
6 CVEsRSS
CVE-2026-32871Critical· 10.0FastMCP is a Pythonic way to build MCP servers and clients
FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifications. The RequestDirector class is responsible for const…
CVE-2026-27124HighFastMCP: Missing Consent Verification in OAuth Proxy Callback Facilitates Confused Deputy Vulnerabilities
FastMCP: Missing Consent Verification in OAuth Proxy Callback Facilitates Confused Deputy Vulnerabilities
CVE-2025-64340Medium· 6.7FastMCP has a Command Injection vulnerability - Gemini CLI
FastMCP has a Command Injection vulnerability - Gemini CLI
CVE-2025-69196Medium· 6.5FastMCP is the standard framework for building MCP applications
FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly respect the resource parameter submitted by the client in the authorization and token request. Instead of issuing the …
CVE-2025-62801MediumFastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name
FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name
CVE-2025-62800MediumFastMCP vulnerable to reflected XSS in client's callback page
FastMCP vulnerable to reflected XSS in client's callback page