Fastmcp
Vendor:
First CVE: Oct 28, 2025 · Active for under a year
6
Total CVEs
More Total CVEs than 83% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 51% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Fastmcp over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 28, 2025
8 months ago
Most Recent CVE
Apr 3, 2026
116 days ago
CVE Severity & Scoring
Fastmcp6 CVEs
50%
33%
17%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (33.3%)
Network4 (66.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (33.3%)
Unknown0 (0.0%)
Required4 (66.7%)
Privileges Required
Low1 (16.7%)
High0 (0.0%)
None5 (83.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-32871CRITICAL FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifica | Apr 2, 2026 | 10.0 | 36 | NO | NO |
CVE-2025-64340HIGH FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, server names containing shell metacharacters (e.g., &) can cause command injection on Windo | Apr 3, 2026 | 7.8 | 28 | NO | NO |
CVE-2025-62801HIGH FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0, a command-injection vulnerability lets any attacker who can influence the server_name fie | Oct 28, 2025 | 7.8 | 25 | NO | NO |
CVE-2026-27124MEDIUM FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, while testing the GitHubProvider OAuth integration, which allows authentication to a FastMC | Apr 3, 2026 | 6.1 | 24 | NO | NO |
CVE-2025-69196MEDIUM FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly respect the resource parameter submitted by the client in the | Mar 16, 2026 | 6.5 | 24 | NO | NO |
CVE-2025-62800MEDIUM FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0 have a reflected cross-site scripting vulnerability in the OAuth client callback page (oau | Oct 28, 2025 | 6.1 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Fastmcp
Top CWEs
Versions
No cataloged versions.