Nixpkgs security tracker

Try the new UI
Login with GitHub

Suggestions search

With package: python313Packages.fastmcp

Found 4 matching suggestions

View:
Compact
Detailed
Permalink CVE-2026-94044
5.5 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): Low (L)
  • Vulnerable System Impact Availability (VA): Low (L)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Exploit Maturity (E): POC (P)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): Low (L)
  • Modified Vulnerable System Impact Availability (MVA): Low (L)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
created 7 hours ago Activity log
  • Created suggestion
03-lovepreetSingh MCP route.ts create_file path traversal

A vulnerability was identified in 03-lovepreetSingh MCP up to f95d035c5317fad81af9828286631053ccb23546. This issue affects the function create_file of the file app/api/mcp/route.ts. Such manipulation of the argument filePath/content leads to path traversal. The attack can be launched remotely. The exploit is publicly available and might be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

MCP
  • ==f95d035c5317fad81af9828286631053ccb23546

Matching in nixpkgs

pkgs.mcpp

Matsui's C preprocessor

  • nixos-unstable -
  • nixos-26.05 -

pkgs.ha-mcp

MCP server for controlling Home Assistant via natural language

  • nixos-unstable -
    • nixos-unstable-small 8.4.3
  • nixos-26.05 -
    • nixos-26.05-small 7.4.1

pkgs.numcpp

Templatized Header Only C++ Implementation of the Python NumPy Library

  • nixos-unstable -
  • nixos-26.05 -

pkgs.fff-mcp

MCP server for the fff file search engine

  • nixos-unstable -

pkgs.pdf-mcp

MCP server that lets AI agents work through large PDFs without overflowing their context

  • nixos-unstable -

pkgs.libXdmcp

X Display Manager Control Protocol library

  • nixos-unstable -
    • nixos-unstable-small 1.1.5
  • nixos-26.05 -
    • nixos-26.05-small 1.1.5

pkgs.libxdmcp

X Display Manager Control Protocol library

  • nixos-unstable -
    • nixos-unstable-small 1.1.5
  • nixos-26.05 -
    • nixos-26.05-small 1.1.5

pkgs.mcp-reva

Headless MCP server exposing Ghidra to AI agents

  • nixos-unstable -
    • nixos-unstable-small 7.3.0

pkgs.mcporter

TypeScript runtime and CLI for connecting to configured Model Context Protocol servers

  • nixos-unstable -
  • nixos-26.05 -

pkgs.mymcplus

PlayStation 2 memory card manager

  • nixos-unstable -
    • nixos-unstable-small 3.0.5
  • nixos-26.05 -
    • nixos-26.05-small 3.0.5

pkgs.azure-mcp

Model Context Protocol server for Azure services

pkgs.mcp-nixos

MCP server for NixOS

  • nixos-unstable -
    • nixos-unstable-small 3.0.1
  • nixos-26.05 -
    • nixos-26.05-small 2.4.3

pkgs.mcp-proxy

MCP server which proxies other MCP servers from stdio to SSE or from SSE to stdio

  • nixos-unstable -
  • nixos-26.05 -

pkgs.mcp-k8s-go

MCP server connecting to Kubernetes

  • nixos-unstable -
    • nixos-unstable-small 0.6.0
  • nixos-26.05 -
    • nixos-26.05-small 0.6.0

pkgs.forgejo-mcp

Model Context Protocol (MCP) server for interacting with the Forgejo REST API

  • nixos-unstable -
  • nixos-26.05 -

pkgs.mcp-gateway

Universal MCP Gateway - Single-port multiplexing with Meta-MCP for ~95% context token savings

  • nixos-unstable -
    • nixos-unstable-small 3.5.1
  • nixos-26.05 -

pkgs.mcp-grafana

MCP server for Grafana

  • nixos-unstable -
    • nixos-unstable-small 1.2.0
  • nixos-26.05 -

pkgs.mcp-searxng

Private web search for AI assistants via SearXNG — supports Claude, Cursor, and any MCP client

  • nixos-unstable -
    • nixos-unstable-small 2.3.0

pkgs.buttplug-mcp

Buttplug.io Model Context Protocol (MCP) Server

  • nixos-unstable -
    • nixos-unstable-small 0.0.1
  • nixos-26.05 -
    • nixos-26.05-small 0.0.1

pkgs.context7-mcp

MCP Server for up-to-date code documentation for LLMs and AI code editors

  • nixos-unstable -
    • nixos-unstable-small 4.0.3
  • nixos-26.05 -
    • nixos-26.05-small 2.2.5

pkgs.lean-lsp-mcp

MCP server for the Lean theorem prover via the Lean LSP

  • nixos-unstable -
  • nixos-26.05 -

pkgs.firecrawl-mcp

A Model Context Protocol (MCP) server that brings Firecrawl to MCP-compatible AI agents

  • nixos-unstable -

pkgs.norgolith-mcp

MCP (Model Context Protocol) server for Norgolith documentation

  • nixos-unstable -
    • nixos-unstable-small 1.2.0

pkgs.aks-mcp-server

Model Context Protocol server for Azure Kubernetes Service

  • nixos-unstable -
  • nixos-26.05 -

pkgs.markitdown-mcp

MCP server for the markitdown library

  • nixos-unstable -
    • nixos-unstable-small 0.1.5
  • nixos-26.05 -
    • nixos-26.05-small 0.1.5

pkgs.mcp-server-git

Model Context Protocol server providing tools to read, search, and manipulate Git repositories programmatically via LLMs

  • nixos-unstable -
  • nixos-26.05 -

pkgs.mcp-server-time

Model Context Protocol server providing tools for time queries and timezone conversions for LLMs

  • nixos-unstable -
  • nixos-26.05 -

pkgs.thunderbird-mcp

MCP server for Thunderbird - enables AI assistants to access email, contacts, and calendars

  • nixos-unstable -
    • nixos-unstable-small 0.7.4
  • nixos-26.05 -
    • nixos-26.05-small 0.5.0

pkgs.gitea-mcp-server

Gitea Model Context Protocol (MCP) Server

  • nixos-unstable -
    • nixos-unstable-small 1.6.0
  • nixos-26.05 -
    • nixos-26.05-small 1.3.0

pkgs.clojure-mcp-light

Simple Clojure tooling for AI coding assistants

  • nixos-unstable -
    • nixos-unstable-small 0.2.2

pkgs.mcp-server-memory

MCP server for enabling memory for Claude through a knowledge graph

  • nixos-unstable -
  • nixos-26.05 -

pkgs.codebase-memory-mcp

High-performance C11 MCP server that indexes codebases into a persistent knowledge graph

  • nixos-unstable -

pkgs.fluxcd-operator-mcp

Kubernetes controller for managing the lifecycle of Flux CD

  • nixos-unstable -
  • nixos-26.05 -

pkgs.haskellPackages.mcp

A Servant-based Model Context Protocol (MCP) server for Haskell

  • nixos-unstable -
  • nixos-26.05 -

pkgs.mcp-language-server

Model Context Protocol server to interact with language servers

  • nixos-unstable -
    • nixos-unstable-small 0.1.1
  • nixos-26.05 -
    • nixos-26.05-small 0.1.1

pkgs.thunderbird-cli-mcp

MCP server that gives full access to your email through Mozilla Thunderbird

  • nixos-unstable -
    • nixos-unstable-small 1.0.2
  • nixos-26.05 -
    • nixos-26.05-small 1.0.2

pkgs.firefox-devtools-mcp

Model Context Protocol server for Firefox DevTools automation

  • nixos-unstable -
    • nixos-unstable-small 0.9.9

pkgs.terraform-mcp-server

Terraform Model Context Protocol (MCP) Server

  • nixos-unstable -
    • nixos-unstable-small 1.3.0
  • nixos-26.05 -
    • nixos-26.05-small 0.5.2

pkgs.python313Packages.mcp

Official Python SDK for Model Context Protocol servers and clients

  • nixos-unstable -
  • nixos-26.05 -

pkgs.python314Packages.mcp

Official Python SDK for Model Context Protocol servers and clients

  • nixos-unstable -
  • nixos-26.05 -

pkgs.haskellPackages.mcp-types

Core types and protocol definitions for the Model Context Protocol (MCP)

  • nixos-unstable -
    • nixos-unstable-small 0.1.1
  • nixos-26.05 -
    • nixos-26.05-small 0.1.1

pkgs.python313Packages.fastapi-mcp

Expose your FastAPI endpoints as Model Context Protocol (MCP) tools, with Auth

  • nixos-unstable -
    • nixos-unstable-small 0.4.0
  • nixos-26.05 -
    • nixos-26.05-small 0.4.0

pkgs.python314Packages.fastapi-mcp

Expose your FastAPI endpoints as Model Context Protocol (MCP) tools, with Auth

  • nixos-unstable -
    • nixos-unstable-small 0.4.0
  • nixos-26.05 -
    • nixos-26.05-small 0.4.0

Package maintainers

Permalink CVE-2025-64340
6.7 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 5 months, 2 weeks ago Activity log
  • Created suggestion
FastMCP has a Command Injection vulnerability - Gemini CLI

FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, server names containing shell metacharacters (e.g., &) can cause command injection on Windows when passed to fastmcp install claude-code or fastmcp install gemini-cli. These install paths use subprocess.run() with a list argument, but on Windows the target CLIs often resolve to .cmd wrappers that are executed through cmd.exe, which interprets metacharacters in the flattened command string. This issue has been patched in version 3.2.0.

Affected products

fastmcp
  • ==< 3.2.0

Matching in nixpkgs

Package maintainers

created 5 months, 2 weeks ago Activity log
  • Created suggestion
FastMCP: Missing Consent Verification in OAuth Proxy Callback Facilitates Confused Deputy Vulnerabilities

FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, while testing the GitHubProvider OAuth integration, which allows authentication to a FastMCP MCP server via a FastMCP OAuthProxy using GitHub OAuth, it was discovered that the FastMCP OAuthProxy does not properly validate the user's consent upon receiving the authorization code from GitHub. In combination with GitHub’s behavior of skipping the consent page for previously authorized clients, this introduces a Confused Deputy vulnerability. This issue has been patched in version 3.2.0.

Affected products

fastmcp
  • ==< 3.2.0

Matching in nixpkgs

Package maintainers

created 5 months, 2 weeks ago Activity log
  • Created suggestion
FastMCP OpenAPI Provider has an SSRF & Path Traversal Vulnerability

FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifications. The RequestDirector class is responsible for constructing HTTP requests to the backend service. A vulnerability exists in the _build_url() method. When an OpenAPI operation defines path parameters (e.g., /api/v1/users/{user_id}), the system directly substitutes parameter values into the URL template string without URL-encoding. Subsequently, urllib.parse.urljoin() resolves the final URL. Since urljoin() interprets ../ sequences as directory traversal, an attacker controlling a path parameter can perform path traversal attacks to escape the intended API prefix and access arbitrary backend endpoints. This results in authenticated SSRF, as requests are sent with the authorization headers configured in the MCP provider. This issue has been patched in version 3.2.0.

Affected products

fastmcp
  • ==< 3.2.0

Matching in nixpkgs

Package maintainers