Jlowin

Fastmcp

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Veröffentlicht 03.04.2026 15:22:17
  • Zuletzt bearbeitet 07.04.2026 13:20:55

FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, while testing the GitHubProvider OAuth integration, which allows authentication to a FastMCP MCP server via a FastMCP OAuthProxy using GitHub OAuth, it was disco...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 03.04.2026 15:16:13
  • Zuletzt bearbeitet 21.04.2026 01:09:14

FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, server names containing shell metacharacters (e.g., &) can cause command injection on Windows when passed to fastmcp install claude-code or fastmcp install gemin...

Exploit
  • EPSS 0.15%
  • Veröffentlicht 02.04.2026 14:52:39
  • Zuletzt bearbeitet 10.04.2026 15:58:07

FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifications. The RequestDirector class is responsible for constructing HTTP ...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 16.03.2026 18:07:06
  • Zuletzt bearbeitet 18.03.2026 15:11:04

FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly respect the resource parameter submitted by the client in the authorization and token request. Instead of issuing the token explici...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 28.10.2025 21:36:41
  • Zuletzt bearbeitet 04.11.2025 13:24:32

FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0, a command-injection vulnerability lets any attacker who can influence the server_name field of an MCP execute arbitrary OS commands on Windows hosts that run f...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 28.10.2025 21:34:40
  • Zuletzt bearbeitet 07.11.2025 01:49:53

FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0 have a reflected cross-site scripting vulnerability in the OAuth client callback page (oauth_callback.py) where unescaped user-controlled values are inserted in...