fastmcpGHSA-rcfx-77hg-w2wv
FastMCP updated to MCP 1.23+ due to CVE-2025-66416
HighPublished Dec 26, 2025
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| fastmcp PyPI | < 2.14.0 | 2.14.0 |
Details and references
There was a recent CVE report on MCP: https://nvd.nist.gov/vuln/detail/CVE-2025-66416. FastMCP does not use any of the affected components of the MCP SDK directly. However, FastMCP versions prior to 2.14.0 did allow MCP SDK versions <1.23 that were vulnerable to CVE-2025-66416. Users should upgrade to FastMCP 2.14.0 or later.
- Severity from
- GitHub (reviewed advisory)
More fastmcp advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 292025 | FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name CVE-2025-62801Mediumfixed in 2.13.0 | Medium | 2.13.0 |
| Oct 292025 | FastMCP vulnerable to reflected XSS in client's callback page CVE-2025-62800Mediumfixed in 2.13.0 | Medium | 2.13.0 |
| Oct 292025 | FastMCP Auth Integration Allows for Confused Deputy Account Takeover GHSA-c2jp-c369-7pvxHighfixed in 2.13.0 | High | 2.13.0 |
| Mar 16 | FastMCP OAuth Proxy token reuse across MCP servers CVE-2025-69196Highfixed in 2.14.2 | High | 2.14.2 |
| Mar 31 | FastMCP has a Command Injection vulnerability - Gemini CLI CVE-2025-64340Medium6.7fixed in 3.2.0 | Medium6.7 | 3.2.0 |
| Mar 31 | FastMCP: Missing Consent Verification in OAuth Proxy Callback Facilitates Confused Deputy Vulnerabilities CVE-2026-27124Highfixed in 3.2.0 | High | 3.2.0 |