Back

MEDIUM

FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name

Published Oct 28, 2025

Description

FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0, a command-injection vulnerability lets any attacker who can influence the server_name field of an MCP execute arbitrary OS commands on Windows hosts that run fastmcp install cursor. This vulnerability is fixed in 2.13.0.

Affected products

Remediation

No remediation recorded yet.

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Oct 28, 2025
Updated Oct 29, 2025
Reserved Oct 22, 2025
CISA Vulnrichment
Updated Oct 29, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitHub_M
Published Oct 28, 2025
Updated Oct 29, 2025
Exploited since n/a
EUVD-2025-36567 GHSA-RJ5C-58RQ-J5G5