FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name
A command-injection vulnerability lets any attacker who can influence the server_name field of an MCP execute arbitrary OS commands on Windows hosts that run fastmcp install cursor