Jlowin maintains a narrowly scoped but strategically deployed product line centered on FastMCP, a tool that bridges language models and external systems through command execution and web access. Vulnerabilities affecting the vendor skew toward serious outcomes and recur across OS command injection, cross-site scripting, incorrect authorization, server-side request forgery, and confused-deputy patterns—a cluster that reflects the inherent trust and mediation demands of an intermediary that translates model outputs into system-level actions. Defenders should treat this vendor's advisories as high-priority given the elevated severity tendency and the sensitive execution context; live exploitation and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jlowin over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-32871CRITICAL FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifica | Apr 2, 2026 | 10.0 | 36 | NO | NO |
CVE-2025-64340HIGH FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, server names containing shell metacharacters (e.g., &) can cause command injection on Windo | Apr 3, 2026 | 7.8 | 25 | NO | NO |
CVE-2025-62801HIGH FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0, a command-injection vulnerability lets any attacker who can influence the server_name fie | Oct 28, 2025 | 7.8 | 25 | NO | NO |
CVE-2025-69196MEDIUM FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly respect the resource parameter submitted by the client in the | Mar 16, 2026 | 6.5 | 24 | NO | NO |
CVE-2025-62800MEDIUM FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0 have a reflected cross-site scripting vulnerability in the OAuth client callback page (oau | Oct 28, 2025 | 6.1 | 22 | NO | NO |
CVE-2026-27124MEDIUM FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, while testing the GitHubProvider OAuth integration, which allows authentication to a FastMC | Apr 3, 2026 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jlowin.
Media articles that mention a CVE ID that affects a product developed by Jlowin — matched by CVE ID, not by vendor name.