FastMCP to standardowa struktura do budowania aplikacji MCP. W wersjach przed 3.2.0 nazwy serwerów zawierające metaznaki powłoki (np. &) mogą spowodować command injection na Windows przy użyciu fastmcp install claude-code lub fastmcp install gemini-cli. Te ścieżki instalacji używają subprocess.run() z argumentem listy, ale na Windows docelowe CLI часто rozwiązują się do opakowania .cmd wykonywane przez cmd.exe, które interpretuje metaznaki w spłaszczonym ciągu polecenia. Problem został naprawiony w wersji 3.2.0.
▸ Pokaż oryginał (EN)
FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, server names containing shell metacharacters (e.g., &) can cause command injection on Windows when passed to fastmcp install claude-code or fastmcp install gemini-cli. These install paths use subprocess.run() with a list argument, but on Windows the target CLIs often resolve to .cmd wrappers that are executed through cmd.exe, which interprets metacharacters in the flattened command string. This issue has been patched in version 3.2.0.
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:HJlowin Fastmcp
APPJlowin< 3.2.0
Powiązane podatności
FastMCP: path traversal i SSRF przez niekodowane parametry ścieżki URL
FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, while testing the Git...
FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not ...
FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0 have a reflected cro...
FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0, a command-injection...