Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2025-62801

FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0, a command-injection vulnerability lets any attacker who can influence the server_name field of an MCP execute arbitrary OS commands on Windows hosts that run fastmcp install cursor. This vulnerability is fixed in 2.13.0.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 5.4%
CVSS Severity
CVSS v3 Score 7.8
Products affected by CVE-2025-62801
  • Jlowin » Fastmcp » Version: 0.1.0
    cpe:2.3:a:jlowin:fastmcp:0.1.0
  • Jlowin » Fastmcp » Version: 0.2.0
    cpe:2.3:a:jlowin:fastmcp:0.2.0
  • Jlowin » Fastmcp » Version: 0.3.0
    cpe:2.3:a:jlowin:fastmcp:0.3.0
  • Jlowin » Fastmcp » Version: 0.3.1
    cpe:2.3:a:jlowin:fastmcp:0.3.1
  • Jlowin » Fastmcp » Version: 0.3.2
    cpe:2.3:a:jlowin:fastmcp:0.3.2
  • Jlowin » Fastmcp » Version: 0.3.3
    cpe:2.3:a:jlowin:fastmcp:0.3.3
  • Jlowin » Fastmcp » Version: 0.3.4
    cpe:2.3:a:jlowin:fastmcp:0.3.4
  • Jlowin » Fastmcp » Version: 0.3.5
    cpe:2.3:a:jlowin:fastmcp:0.3.5
  • Jlowin » Fastmcp » Version: 0.4.0
    cpe:2.3:a:jlowin:fastmcp:0.4.0
  • Jlowin » Fastmcp » Version: 0.4.1
    cpe:2.3:a:jlowin:fastmcp:0.4.1
  • Jlowin » Fastmcp » Version: 1.0
    cpe:2.3:a:jlowin:fastmcp:1.0
  • Jlowin » Fastmcp » Version: 2.0.0
    cpe:2.3:a:jlowin:fastmcp:2.0.0
  • Jlowin » Fastmcp » Version: 2.1.0
    cpe:2.3:a:jlowin:fastmcp:2.1.0
  • Jlowin » Fastmcp » Version: 2.1.1
    cpe:2.3:a:jlowin:fastmcp:2.1.1
  • Jlowin » Fastmcp » Version: 2.1.2
    cpe:2.3:a:jlowin:fastmcp:2.1.2
  • Jlowin » Fastmcp » Version: 2.10.0
    cpe:2.3:a:jlowin:fastmcp:2.10.0
  • Jlowin » Fastmcp » Version: 2.10.1
    cpe:2.3:a:jlowin:fastmcp:2.10.1
  • Jlowin » Fastmcp » Version: 2.10.2
    cpe:2.3:a:jlowin:fastmcp:2.10.2
  • Jlowin » Fastmcp » Version: 2.10.3
    cpe:2.3:a:jlowin:fastmcp:2.10.3
  • Jlowin » Fastmcp » Version: 2.10.4
    cpe:2.3:a:jlowin:fastmcp:2.10.4
  • Jlowin » Fastmcp » Version: 2.10.5
    cpe:2.3:a:jlowin:fastmcp:2.10.5
  • Jlowin » Fastmcp » Version: 2.10.6
    cpe:2.3:a:jlowin:fastmcp:2.10.6
  • Jlowin » Fastmcp » Version: 2.11.0
    cpe:2.3:a:jlowin:fastmcp:2.11.0
  • Jlowin » Fastmcp » Version: 2.11.1
    cpe:2.3:a:jlowin:fastmcp:2.11.1
  • Jlowin » Fastmcp » Version: 2.11.2
    cpe:2.3:a:jlowin:fastmcp:2.11.2
  • Jlowin » Fastmcp » Version: 2.11.3
    cpe:2.3:a:jlowin:fastmcp:2.11.3
  • Jlowin » Fastmcp » Version: 2.12.0
    cpe:2.3:a:jlowin:fastmcp:2.12.0
  • Jlowin » Fastmcp » Version: 2.12.1
    cpe:2.3:a:jlowin:fastmcp:2.12.1
  • Jlowin » Fastmcp » Version: 2.12.2
    cpe:2.3:a:jlowin:fastmcp:2.12.2
  • Jlowin » Fastmcp » Version: 2.12.3
    cpe:2.3:a:jlowin:fastmcp:2.12.3
  • Jlowin » Fastmcp » Version: 2.12.4
    cpe:2.3:a:jlowin:fastmcp:2.12.4
  • Jlowin » Fastmcp » Version: 2.12.5
    cpe:2.3:a:jlowin:fastmcp:2.12.5
  • Jlowin » Fastmcp » Version: 2.2.0
    cpe:2.3:a:jlowin:fastmcp:2.2.0
  • Jlowin » Fastmcp » Version: 2.2.1
    cpe:2.3:a:jlowin:fastmcp:2.2.1
  • Jlowin » Fastmcp » Version: 2.2.10
    cpe:2.3:a:jlowin:fastmcp:2.2.10
  • Jlowin » Fastmcp » Version: 2.2.2
    cpe:2.3:a:jlowin:fastmcp:2.2.2
  • Jlowin » Fastmcp » Version: 2.2.3
    cpe:2.3:a:jlowin:fastmcp:2.2.3
  • Jlowin » Fastmcp » Version: 2.2.4
    cpe:2.3:a:jlowin:fastmcp:2.2.4
  • Jlowin » Fastmcp » Version: 2.2.5
    cpe:2.3:a:jlowin:fastmcp:2.2.5
  • Jlowin » Fastmcp » Version: 2.2.6
    cpe:2.3:a:jlowin:fastmcp:2.2.6
  • Jlowin » Fastmcp » Version: 2.2.7
    cpe:2.3:a:jlowin:fastmcp:2.2.7
  • Jlowin » Fastmcp » Version: 2.2.8
    cpe:2.3:a:jlowin:fastmcp:2.2.8
  • Jlowin » Fastmcp » Version: 2.2.9
    cpe:2.3:a:jlowin:fastmcp:2.2.9
  • Jlowin » Fastmcp » Version: 2.3.0
    cpe:2.3:a:jlowin:fastmcp:2.3.0
  • Jlowin » Fastmcp » Version: 2.3.1
    cpe:2.3:a:jlowin:fastmcp:2.3.1
  • Jlowin » Fastmcp » Version: 2.3.2
    cpe:2.3:a:jlowin:fastmcp:2.3.2
  • Jlowin » Fastmcp » Version: 2.3.3
    cpe:2.3:a:jlowin:fastmcp:2.3.3
  • Jlowin » Fastmcp » Version: 2.3.4
    cpe:2.3:a:jlowin:fastmcp:2.3.4
  • Jlowin » Fastmcp » Version: 2.3.5
    cpe:2.3:a:jlowin:fastmcp:2.3.5
  • Jlowin » Fastmcp » Version: 2.4.0
    cpe:2.3:a:jlowin:fastmcp:2.4.0
  • Jlowin » Fastmcp » Version: 2.5.0
    cpe:2.3:a:jlowin:fastmcp:2.5.0
  • Jlowin » Fastmcp » Version: 2.5.1
    cpe:2.3:a:jlowin:fastmcp:2.5.1
  • Jlowin » Fastmcp » Version: 2.5.2
    cpe:2.3:a:jlowin:fastmcp:2.5.2
  • Jlowin » Fastmcp » Version: 2.6.0
    cpe:2.3:a:jlowin:fastmcp:2.6.0
  • Jlowin » Fastmcp » Version: 2.6.1
    cpe:2.3:a:jlowin:fastmcp:2.6.1
  • Jlowin » Fastmcp » Version: 2.7.0
    cpe:2.3:a:jlowin:fastmcp:2.7.0
  • Jlowin » Fastmcp » Version: 2.7.1
    cpe:2.3:a:jlowin:fastmcp:2.7.1
  • Jlowin » Fastmcp » Version: 2.8.0
    cpe:2.3:a:jlowin:fastmcp:2.8.0
  • Jlowin » Fastmcp » Version: 2.8.1
    cpe:2.3:a:jlowin:fastmcp:2.8.1
  • Jlowin » Fastmcp » Version: 2.9.0
    cpe:2.3:a:jlowin:fastmcp:2.9.0
  • Jlowin » Fastmcp » Version: 2.9.1
    cpe:2.3:a:jlowin:fastmcp:2.9.1
  • Jlowin » Fastmcp » Version: 2.9.2
    cpe:2.3:a:jlowin:fastmcp:2.9.2


Contact Us

Shodan ® - All rights reserved