Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Jlowin

First CVE: Oct 28, 2025Active for: 1 yearTotal CVEs: 6

Jlowin maintains a narrowly scoped but strategically deployed product line centered on FastMCP, a tool that bridges language models and external systems through command execution and web access. Vulnerabilities affecting the vendor skew toward serious outcomes and recur across OS command injection, cross-site scripting, incorrect authorization, server-side request forgery, and confused-deputy patterns—a cluster that reflects the inherent trust and mediation demands of an intermediary that translates model outputs into system-level actions. Defenders should treat this vendor's advisories as high-priority given the elevated severity tendency and the sensitive execution context; live exploitation and severity counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
3.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Jlowin over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 28, 2025
8 months ago
Most Recent CVE
Apr 3, 2026
112 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-32871CRITICAL
FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifica
Apr 2, 202610.036NONO
CVE-2025-64340HIGH
FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, server names containing shell metacharacters (e.g., &) can cause command injection on Windo
Apr 3, 20267.825NONO
CVE-2025-62801HIGH
FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0, a command-injection vulnerability lets any attacker who can influence the server_name fie
Oct 28, 20257.825NONO
CVE-2025-69196MEDIUM
FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly respect the resource parameter submitted by the client in the
Mar 16, 20266.524NONO
CVE-2025-62800MEDIUM
FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0 have a reflected cross-site scripting vulnerability in the OAuth client callback page (oau
Oct 28, 20256.122NONO
CVE-2026-27124MEDIUM
FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, while testing the GitHubProvider OAuth integration, which allows authentication to a FastMC
Apr 3, 20266.121NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
50%
33%
17%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (33.3%)
Network4 (66.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (33.3%)
Unknown0 (0.0%)
Required4 (66.7%)
Privileges Required
Low1 (16.7%)
High0 (0.0%)
None5 (83.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Jlowin.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Jlowin — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Jlowin's Products

View all 1 CNAs →

Top CWEs