Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2025-64340: Command injection in FastMCP install commands on Windows

FastMCP versions prior to 3.2.0 allow command injection on Windows when a server name containing shell metacharacters is passed to `fastmcp install claude-code` or `fastmcp install gemini-cli`, because the target CLIs resolve to .cmd wrappers executed through cmd.exe. The issue was patched in FastMCP 3.2.0.

Disclosed 3 April 2026 · Record updated 13 September 2026

Impact

Attacker-influenced server names could lead to arbitrary command execution on Windows systems running the affected FastMCP install commands.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2025-64340