CVE-2025-64340
CVE-2025-64340 is a medium-severity vulnerability in Jlowin Fastmcp with a CVSS 3.x base score of 6.7. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-78.
Key facts
- Severity: Medium (CVSS 3.x base score 6.7)
- EPSS exploit prediction: 1% (53rd percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2025-209207
- Weakness: CWE-78
- Affected product: Jlowin Fastmcp
- Published:
- Last modified:
Description
FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, server names containing shell metacharacters (e.g., &) can cause command injection on Windows when passed to fastmcp install claude-code or fastmcp install gemini-cli. These install paths use subprocess.run() with a list argument, but on Windows the target CLIs often resolve to .cmd wrappers that are executed through cmd.exe, which interprets metacharacters in the flattened command string. This issue has been patched in version 3.2.0.
Frequently asked questions
- What is CVE-2025-64340?
- FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, server names containing shell metacharacters (e.g., &) can cause command injection on Windows when passed to fastmcp install claude-code or fastmcp install gemini-cli. These install paths use subprocess.run() with a list argument, but on Windows the target CLIs often resolve to .cmd wrappers that are executed through cmd.exe, which interprets metacharacters in the flattened command string. This issue has been patched in version 3.2.0.
- How severe is CVE-2025-64340?
- CVE-2025-64340 has a CVSS 3.x base score of 6.7, rated medium severity. It is exploitable over local access with high attack complexity, requires low privileges and user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2025-64340 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (53rd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2025-64340?
- CVE-2025-64340 affects Jlowin Fastmcp. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2025-64340?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2025-64340 have an EU (EUVD) identifier?
- Yes. CVE-2025-64340 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2025-209207.
- When was CVE-2025-64340 published?
- CVE-2025-64340 was published on 2026-04-03 and last updated on 2026-07-24.
References
- https://github.com/PrefectHQ/fastmcp/pull/3522
- https://github.com/PrefectHQ/fastmcp/security/advisories/GHSA-m8x7-r2rg-vh5g
Affected products (1)
- cpe:2.3:a:jlowin:fastmcp:*:*:*:*:*:*:*:*
More vulnerabilities in Jlowin Fastmcp
- CVE-2026-32871 — Critical (CVSS 10.0): FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP…
- CVE-2025-62801 — High (CVSS 7.8): FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0, a command-injection…
- CVE-2025-69196 — Medium (CVSS 6.5): FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly…
- CVE-2026-27124 — Medium (CVSS 6.1): FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, while testing the…
- CVE-2025-62800 — Medium (CVSS 6.1): FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0 have a reflected cross-site…
All CVEs affecting Jlowin Fastmcp →
Other CWE-78 (OS Command Injection) vulnerabilities
- CVE-2026-100382 — Critical (CVSS 10.0): Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia…
- CVE-2026-77521 — Critical (CVSS 10.0): MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool,…
- CVE-2026-82004 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS…
- CVE-2026-76197 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS…
- CVE-2026-76195 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS…
- CVE-2026-19188 — Critical (CVSS 10.0): A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The…