Junglewise Threat Intelligence

CVE-2025-62800: PYSEC-2026-1364 - FastMCP vulnerable to reflected XSS in client's callback page

CVE-2025-62800 · Severity: medium · CVSS 4 · Published 2026-07-07

Technologies: fastmcp (PyPI). Vendors: PyPI.

Executive brief

FastMCP vulnerable to reflected XSS in client's callback page

Affected products

  • PyPI fastmcp

Related threats