Логотип exploitDog
bind:CVE-2025-62801
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-62801

Количество 2

Количество 2

nvd логотип

CVE-2025-62801

3 месяца назад

FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0, a command-injection vulnerability lets any attacker who can influence the server_name field of an MCP execute arbitrary OS commands on Windows hosts that run fastmcp install cursor. This vulnerability is fixed in 2.13.0.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-rj5c-58rq-j5g5

3 месяца назад

FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-62801

FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0, a command-injection vulnerability lets any attacker who can influence the server_name field of an MCP execute arbitrary OS commands on Windows hosts that run fastmcp install cursor. This vulnerability is fixed in 2.13.0.

CVSS3: 7.8
0%
Низкий
3 месяца назад
github логотип
GHSA-rj5c-58rq-j5g5

FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name

0%
Низкий
3 месяца назад

Уязвимостей на страницу