CVE-2025-62801EPSS p12.3%
CVE-2025-62801CVE-2025-62801
jlowin / fastmcp
Description
FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0, a command-injection vulnerability lets any attacker who can influence the server_name field of an MCP execute arbitrary OS commands on Windows hosts that run fastmcp install cursor. This vulnerability is fixed in 2.13.0.
Scoring
| CVSS | 7.8 () |
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.23% probability of exploitation · percentile 12.3% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-30 |