Skip to content

Conversation

@BacklineAI
Copy link

πŸ” Security Vulnerability Fixes

βœ… This pull request was created and verified by Backline to fix security vulnerabilities in your dependencies.
We recently conducted research to identify high-impact OSS projects that contribute significantly to the community. As part of this, we ran microsoft-UFO through our platform to see if we could help clear out any lingering security vulnerabilities.


πŸ“¦ Package Updates & Vulnerability Fixes

fastmcp

v2.11.3 β†’ 2.14.0

  • 🟧 GHSA-c2jp-c369-7pvx - FastMCP Auth Integration Allows for Confused Deputy Account Takeover.
  • 🟨 CVE-2025-62800 - FastMCP vulnerable to reflected XSS in client's callback page.
  • 🟨 CVE-2025-62801 - FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name.

Legend: πŸŸ₯ Critical | 🟧 High | 🟨 Medium | 🟦 Low


Backline is here to help accelerate the remediation of your security backlog. Here's how we operate:

πŸ“₯ Fetch Findings – Gather security issues
πŸ” Analyze Findings – Understand the context and impact
πŸ“ Plan Remediation – Generate a safe and effective fix strategy
πŸ‘· Apply Fix – Implement the remediation in code
πŸ§ͺ Validate Code – Ensure the changes maintain code quality and integrity
βœ… Verify – Run tests to ensure correctness and stability

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant