PatchSiren

jlowin CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH jlowin CVE published 2026-04-03

CVE-2026-27124

CVE-2026-27124 is a high-severity vulnerability in FastMCP's OAuthProxy, enabling Confused Deputy attacks via GitHub OAuth. The vulnerability was patched in version 3.2.0. Affected product deployments should be identified, and owners assigned for follow-up. Official advisories and CVE records should be reviewed to validate affected scope, severity, and vendor guidance. The vulnerability allows an attacker [truncated]

MEDIUM jlowin CVE published 2026-04-03

CVE-2025-64340

CVE-2025-64340 is a command injection vulnerability in FastMCP, a framework for building MCP applications. Prior to version 3.2.0, server names containing shell metacharacters can cause command injection on Windows when passed to certain install commands. This issue has been patched in version 3.2.0. Affected users, especially those using Windows, should be aware of this vulnerability and take steps to mi [truncated]

HIGH jlowin CVE published 2026-03-16

CVE-2025-69196

CVE-2025-69196 is a high-severity vulnerability in FastMCP, a framework for building MCP applications. The issue allows an attacker to obtain a token for an MCP server by exploiting the improper handling of the resource parameter in authorization and token requests. This vulnerability has been patched in version 2.14.2. The CVSS score for this vulnerability is 7.4, indicating a high level of severity. The [truncated]