
CVE-2025-64340 FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, server names containing shell metacharacters (e.g., &) can cause command inje… https://www.cve.org/CVERecord?id=CVE-2025-64340
Post summary
The text announces a command injection vulnerability in FastMCP that affects versions before 3.2.0 and notes that upgrading to 3.2.0 or later resolves the issue.
