| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-27124 | FastMCP: Missing Consent Verification in OAuth Proxy Callback Facilitates Confused Deputy Vulnerabilities | jlowin | fastmcp | - | - | 2026-04-03 15:22:17 | Deep Dive |
| CVE-2025-64340 | FastMCP has a Command Injection vulnerability - Gemini CLI | jlowin | fastmcp | Medium | 6.7 | 2026-04-03 15:16:14 | Deep Dive |
| CVE-2025-69196 | FastMCP OAuth Proxy token reuse across MCP servers | jlowin | fastmcp | - | - | 2026-03-16 18:07:06 | Deep Dive |
| CVE-2025-62801 | FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name | jlowin | fastmcp | - | - | 2025-10-28 21:36:41 | Deep Dive |
| CVE-2025-62800 | FastMCP vulnerable to reflected XSS in client's callback page | jlowin | fastmcp | - | - | 2025-10-28 21:34:40 | Deep Dive |