Junglewise Threat Intelligence

CVE-2025-62801: PYSEC-2026-1365 - FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name

CVE-2025-62801 · Severity: medium · CVSS 4 · Published 2026-07-07

Technologies: fastmcp (PyPI). Vendors: PyPI.

Executive brief

FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name

Affected products

  • PyPI fastmcp

Related threats