Vendorsjlowinfastmcpall versions
Vulnerabilities

jlowin Fastmcp

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2026-32871
FastMCP OpenAPI Provider has an SSRF & Path Traversal Vulnerability
Published 2026-04-02 · Modified
10.0EPSS 0.014
CVE-2026-27124
FastMCP: Missing Consent Verification in OAuth Proxy Callback Facilitates Confused Deputy Vulnerabilities
Published 2026-04-03 · Analyzed
8.2EPSS 0.003
CVE-2025-64340
FastMCP has a Command Injection vulnerability - Gemini CLI
Published 2026-04-03 · Analyzed
7.8EPSS 0.007
CVE-2025-62801
FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name
Published 2025-10-28 · Analyzed
7.8EPSS 0.002
CVE-2025-69196
FastMCP OAuth Proxy token reuse across MCP servers
Published 2026-03-16 · Modified
7.4EPSS 0.004
CVE-2025-62800
FastMCP vulnerable to reflected XSS in client's callback page
Published 2025-10-28 · Analyzed
6.1EPSS 0.003