{"id":"GHSA-rcfx-77hg-w2wv","aliases":[],"url":"https://o3.security/vulnerability/GHSA-rcfx-77hg-w2wv","summary":"FastMCP updated to MCP 1.23+ due to CVE-2025-66416","details":"There was a recent CVE report on MCP: https://nvd.nist.gov/vuln/detail/CVE-2025-66416. \n\nFastMCP does not use any of the affected components of the MCP SDK directly. However, FastMCP versions prior to 2.14.0 did allow MCP SDK versions <1.23 that were vulnerable to CVE-2025-66416. Users should upgrade to FastMCP 2.14.0 or later.","published":"2025-12-26T23:20:50Z","modified":"2025-12-26T23:27:27.257304Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"fastmcp","fixedVersion":"2.14.0"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/jlowin/fastmcp/security/advisories/GHSA-rcfx-77hg-w2wv"},{"type":"WEB","url":"https://github.com/modelcontextprotocol/python-sdk/security/advisories/GHSA-9h52-p55h-vw2f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66416"},{"type":"PACKAGE","url":"https://github.com/jlowin/fastmcp"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-12-26T23:27:27.257304Z"}}