CVE-2025-62801: FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name
A command-injection vulnerability lets any attacker who can influence the server_name field of an MCP execute arbitrary OS commands on Windows hosts that run fastmcp install cursor
References
Code Behaviors & Features
Detect and mitigate CVE-2025-62801 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →