© 2025-2026 PySpect
First version without a known vulnerability: 3.2.0
FastMCP OpenAPI Provider has an SSRF & Path Traversal Vulnerability
Fixed in: 3.2.0
FastMCP: Missing Consent Verification in OAuth Proxy Callback Facilitates Confused Deputy Vulnerabilities
Fixed in: 3.2.0
FastMCP has a Command Injection vulnerability - Gemini CLI
Fixed in: 3.2.0
FastMCP OAuth Proxy token reuse across MCP servers
Fixed in: 2.14.2
FastMCP updated to MCP 1.23+ due to CVE-2025-66416
Fixed in: 2.14.0
FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name
Fixed in: 2.13.0
FastMCP vulnerable to reflected XSS in client's callback page
Fixed in: 2.13.0
FastMCP Auth Integration Allows for Confused Deputy Account Takeover
Fixed in: 2.13.0