{"schema_version":1,"title":"fastmcp (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 6 vulnerabilities in fastmcp (PyPI): 0 in the last 7 days and 2 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2025-62801, was published on 7 July 2026.","url":"https://junglewise.ai/threats/technologies/fastmcp","json_url":"https://junglewise.ai/threats/technologies/fastmcp.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/fastmcp","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":6,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":2,"last_365_days":6},"latest":[{"cve":"CVE-2025-62801","cvss":4,"epss":0.0021,"slug":"cve-2025-62801-fastmcp-vulnerable-to-windows-command-injection-in-fastmcp-cursor","title":"PYSEC-2026-1365 - FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:08.659725+00:00","url":"https://junglewise.ai/threats/cve-2025-62801-fastmcp-vulnerable-to-windows-command-injection-in-fastmcp-cursor"},{"cve":"CVE-2025-62800","cvss":4,"epss":0.0026,"slug":"cve-2025-62800-fastmcp-vulnerable-to-reflected-xss-in-client-s-callback-page","title":"PYSEC-2026-1364 - FastMCP vulnerable to reflected XSS in client's callback page","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:08.608105+00:00","url":"https://junglewise.ai/threats/cve-2025-62800-fastmcp-vulnerable-to-reflected-xss-in-client-s-callback-page"},{"cve":"CVE-2026-27124","cvss":6.1,"epss":0.0031,"slug":"cve-2026-27124-fastmcp-confused-deputy-vulnerability-in-oauthproxy-callback","title":"FastMCP confused deputy vulnerability in OAuthProxy callback","severity":"medium","exploited":false,"published_at":"2026-04-03T16:16:36.453+00:00","url":"https://junglewise.ai/threats/cve-2026-27124-fastmcp-confused-deputy-vulnerability-in-oauthproxy-callback"},{"cve":"CVE-2025-64340","cvss":6.7,"epss":0.0074,"slug":"cve-2025-64340-prefecthq-fastmcp-command-injection-in-cli-install-on-windows","title":"PrefectHQ FastMCP command injection in CLI install on Windows","severity":"medium","exploited":false,"published_at":"2026-04-03T16:16:23.01+00:00","url":"https://junglewise.ai/threats/cve-2025-64340-prefecthq-fastmcp-command-injection-in-cli-install-on-windows"},{"cve":"CVE-2026-32871","cvss":10,"epss":0.0137,"slug":"cve-2026-32871-prefecthq-fastmcp-path-traversal-and-ssrf-in-openapiprovider","title":"PrefectHQ FastMCP path traversal and SSRF in OpenAPIProvider","severity":"critical","exploited":false,"published_at":"2026-04-02T15:16:38.74+00:00","url":"https://junglewise.ai/threats/cve-2026-32871-prefecthq-fastmcp-path-traversal-and-ssrf-in-openapiprovider"},{"cve":"CVE-2025-69196","cvss":6.5,"epss":0.0036,"slug":"cve-2025-69196-prefecthq-fastmcp-improper-resource-handling-in-oauth-proxy","title":"PrefectHQ FastMCP improper resource handling in OAuth Proxy","severity":"medium","exploited":false,"published_at":"2026-03-16T19:16:14.397+00:00","url":"https://junglewise.ai/threats/cve-2025-69196-prefecthq-fastmcp-improper-resource-handling-in-oauth-proxy"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"plone (PyPI)","slug":"pypi-plone","vulnerabilities":101,"url":"https://junglewise.ai/threats/technologies/pypi-plone"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"exiv2 (PyPI)","slug":"exiv2","vulnerabilities":85,"url":"https://junglewise.ai/threats/technologies/exiv2"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"}],"technology":{"hub":true,"name":"fastmcp (PyPI)","slug":"fastmcp","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"homepage":"https://pypi.org/project/fastmcp/","repo_url":"https://github.com/jlowin/fastmcp","description":"A Python framework for building Model Context Protocol (MCP) servers.","url":"https://junglewise.ai/threats/technologies/fastmcp"},"most_severe":[{"cve":"CVE-2026-32871","cvss":10,"epss":0.0137,"slug":"cve-2026-32871-prefecthq-fastmcp-path-traversal-and-ssrf-in-openapiprovider","title":"PrefectHQ FastMCP path traversal and SSRF in OpenAPIProvider","severity":"critical","exploited":false,"published_at":"2026-04-02T15:16:38.74+00:00","url":"https://junglewise.ai/threats/cve-2026-32871-prefecthq-fastmcp-path-traversal-and-ssrf-in-openapiprovider"},{"cve":"CVE-2025-64340","cvss":6.7,"epss":0.0074,"slug":"cve-2025-64340-prefecthq-fastmcp-command-injection-in-cli-install-on-windows","title":"PrefectHQ FastMCP command injection in CLI install on Windows","severity":"medium","exploited":false,"published_at":"2026-04-03T16:16:23.01+00:00","url":"https://junglewise.ai/threats/cve-2025-64340-prefecthq-fastmcp-command-injection-in-cli-install-on-windows"},{"cve":"CVE-2025-69196","cvss":6.5,"epss":0.0036,"slug":"cve-2025-69196-prefecthq-fastmcp-improper-resource-handling-in-oauth-proxy","title":"PrefectHQ FastMCP improper resource handling in OAuth Proxy","severity":"medium","exploited":false,"published_at":"2026-03-16T19:16:14.397+00:00","url":"https://junglewise.ai/threats/cve-2025-69196-prefecthq-fastmcp-improper-resource-handling-in-oauth-proxy"},{"cve":"CVE-2026-27124","cvss":6.1,"epss":0.0031,"slug":"cve-2026-27124-fastmcp-confused-deputy-vulnerability-in-oauthproxy-callback","title":"FastMCP confused deputy vulnerability in OAuthProxy callback","severity":"medium","exploited":false,"published_at":"2026-04-03T16:16:36.453+00:00","url":"https://junglewise.ai/threats/cve-2026-27124-fastmcp-confused-deputy-vulnerability-in-oauthproxy-callback"},{"cve":"CVE-2025-62800","cvss":4,"epss":0.0026,"slug":"cve-2025-62800-fastmcp-vulnerable-to-reflected-xss-in-client-s-callback-page","title":"PYSEC-2026-1364 - FastMCP vulnerable to reflected XSS in client's callback page","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:08.608105+00:00","url":"https://junglewise.ai/threats/cve-2025-62800-fastmcp-vulnerable-to-reflected-xss-in-client-s-callback-page"},{"cve":"CVE-2025-62801","cvss":4,"epss":0.0021,"slug":"cve-2025-62801-fastmcp-vulnerable-to-windows-command-injection-in-fastmcp-cursor","title":"PYSEC-2026-1365 - FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:08.659725+00:00","url":"https://junglewise.ai/threats/cve-2025-62801-fastmcp-vulnerable-to-windows-command-injection-in-fastmcp-cursor"}],"generated_at":"2026-09-27T03:07:00.185062+00:00"}